Upgrade to the latest version of Ahsay, currently (

Technical details

Path traversal the following page can be used to browse the server the AhsayCBS v8.1.0.50 is installed on.

On the page “File Explorer” it is possible to change the directory in the Javascript code. When this is done to lets say C: we can browse the whole server.

Screenshot: Changing the Javascript to C:\\:

Changing the Javascript

Screenshot: If we now click the link “C:\Program Files\AhsayCBS” we will be redirected to “C:": Content of c: