Files
CVEs-PoC/2021/CVE-2021-27197.md
2025-09-29 21:09:30 +02:00

903 B

CVE-2021-27197

Description

DSUtility.dll in Pelco Digital Sentry Server before 7.19.67 has an arbitrary file write vulnerability. The AppendToTextFile method doesn't check if it's being called from the application or from a malicious user. The vulnerability is triggered when a remote attacker crafts an HTML page (e.g., with "OBJECT classid=" and "<SCRIPT language='vbscript'>") to overwrite arbitrary files.

POC

Reference

Github

No PoCs found on GitHub currently.