Local File Inclusion and Remote Code Execution in GeoVision GeoWebServer
CVE-2021-47795
Key Information:
- Vendor
Geovision
- Status
- Vendor
- CVE Published:
- 15 January 2026
Badges
What is CVE-2021-47795?
GeoVision GeoWebServer version 5.3.3 is susceptible to multiple vulnerabilities that can lead to local file inclusion, cross-site scripting (XSS), and remote code execution. Attackers can exploit the WebStrings.srf endpoint by leveraging improper input sanitization, allowing for path traversal and injection attacks. By manipulating input parameters, attackers can gain unauthorized access to sensitive system files and execute arbitrary malicious scripts on the server.
Affected Version(s)
GeoVision Geowebserver <= 5.3.3
Exploit Proof of Concept (PoC)
PoC code is written by security researchers to demonstrate the vulnerability can be exploited. PoC code is also a key component for weaponization which could lead to ransomware.
References
CVSS V4
Timeline
- ๐ก
Public PoC available
- ๐พ
Exploit known to exist
Vulnerability published
Vulnerability Reserved
