CVE-2017-6195
- EPSS 0.07%
- Veröffentlicht 18.05.2017 06:29:00
- Zuletzt bearbeitet 20.04.2025 01:37:25
Ipswitch MOVEit Transfer (formerly DMZ) allows pre-authentication blind SQL injection. The fixed versions are MOVEit Transfer 2017 9.0.0.201, MOVEit DMZ 8.3.0.30, and MOVEit DMZ 8.2.0.20.
CVE-2015-7676
- EPSS 0.02%
- Veröffentlicht 15.04.2016 15:59:01
- Zuletzt bearbeitet 12.04.2025 10:46:40
Ipswitch MOVEit File Transfer (formerly DMZ) 8.1 and earlier, when configured to support file view on download, allows remote authenticated users to conduct cross-site scripting (XSS) attacks by uploading HTML files.
CVE-2015-7680
- EPSS 0.03%
- Veröffentlicht 10.02.2016 15:59:04
- Zuletzt bearbeitet 12.04.2025 10:46:40
Ipswitch MOVEit DMZ before 8.2 provides different error messages for authentication attempts depending on whether the user account exists, which allows remote attackers to enumerate usernames via a series of SOAP requests to machine.aspx.
CVE-2015-7677
- EPSS 0.02%
- Veröffentlicht 10.02.2016 15:59:01
- Zuletzt bearbeitet 12.04.2025 10:46:40
The MOVEitISAPI service in Ipswitch MOVEit DMZ before 8.2 provides different error messages depending on whether a FileID exists, which allows remote authenticated users to enumerate FileIDs via the X-siLock-FileID parameter in a download action to M...
CVE-2015-7675
- EPSS 0.01%
- Veröffentlicht 10.02.2016 15:59:00
- Zuletzt bearbeitet 12.04.2025 10:46:40
The "Send as attachment" feature in Ipswitch MOVEit DMZ before 8.2 and MOVEit Mobile before 1.2.2 allow remote authenticated users to bypass authorization and read uploaded files via a valid FileID in the (1) serverFileIds parameter to mobile/sendMsg...