PT-2015-6390 · Acunetix · Acunetix Web Vulnerability Scanner

Daniele Linguaglossa

·

Publicado

2015-12-17

·

Atualizado

2020-08-03

·

CVE-2015-4027

CVSS v2.0

7.2

Alta

VetorAV:L/AC:L/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions Acunetix Web Vulnerability Scanner (WVS) versions prior to 10 build 20151125
Description The issue allows local users to gain privileges via a command parameter in the reporttemplate property in a params JSON object to the "api/addScan" API endpoint.
Recommendations For versions prior to 10 build 20151125, update to a version newer than 10 build 20151125 to resolve the issue. As a temporary workaround, consider restricting access to the "api/addScan" API endpoint to minimize the risk of exploitation. Avoid using the reporttemplate property in the params JSON object until the issue is resolved.

Exploit

Correção

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2015-4027

Produtos afetados

Acunetix Web Vulnerability Scanner