5.3

CVE-2016-9499

Exploit

The Accellion FTP server prior to version FTA_9_12_220 is vulnerable to cross-site scripting.

Accellion FTP server prior to version FTA_9_12_220 only returns the username in the server response if the username is invalid. An attacker may use this information to determine valid user accounts and enumerate them.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
AccellionFtp Server Version < fta_9_12_220
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 7.77% 0.939
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
nvd@nist.gov 5.3 3.9 1.4
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
nvd@nist.gov 5 10 2.9
AV:N/AC:L/Au:N/C:P/I:N/A:N
CWE-200 Exposure of Sensitive Information to an Unauthorized Actor

The product exposes sensitive information to an actor that is not explicitly authorized to have access to that information.

CWE-204 Observable Response Discrepancy

The product provides different responses to incoming requests in a way that reveals internal state information to an unauthorized actor outside of the intended control sphere.

https://www.kb.cert.org/vuls/id/745607
Third Party Advisory
US Government Resource
https://www.qualys.com/2016/12/06/qsa-2016-12-06/qsa-2016-12-06.pdf
Third Party Advisory
Exploit
https://www.securityfocus.com/bid/96154
Third Party Advisory
VDB Entry