CVE-2015-4027
CVE-2015-4027
The AcuWVSSchedulerv10 service in Acunetix Web Vulnerability Scanner (WVS) before 10 build 20151125 allows local users to gain privileges via a command parameter in the reporttemplate property in a params JSON object to api/addScan.
Affected products
n/a · n/apublic PoCs found — 3
cve_referencepacketstormsecurity.com/files/134602/Acunetix-WVS-10-Local-Privilege-Escalation.htmlunverifiedcve_referencewww.exploit-db.com/exploits/38847/unverifiedexploitdbwww.exploit-db.com/exploits/38847unverified⚠ Public resources, to assess the exposure of systems you control or are authorized to test. Test only with authorization.
Want to know if your infrastructure is exposed to this?
Talk to TrueHacking →