The AcuWVSSchedulerv10 service in Acunetix Web Vulnerability Scanner (WVS) before 10 build 20151125 allows local users to gain privileges via a command parameter in the reporttemplate property in a params JSON object to api/addScan.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Web_vulnerability_scanner | Acunetix | * | 10 (including) |