Описание
Local file inclusion exists in Kaseya VSA before 9.5.6.
Local file inclusion exists in Kaseya VSA before 9.5.6.
Связанные уязвимости
CVSS3: 6.5
nvd
больше 4 лет назад
Semi-authenticated local file inclusion The contents of arbitrary files can be returned by the webserver Example request: `https://x.x.x.x/KLC/js/Kaseya.SB.JS/js.aspx?path=C:\Kaseya\WebPages\dl.asp` A valid sessionId is required but can be easily obtained via CVE-2021-30118