Ipswitch

Moveit Dmz

5 vulnerabilities found.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 0.07%
  • Published 18.05.2017 06:29:00
  • Last modified 20.04.2025 01:37:25

Ipswitch MOVEit Transfer (formerly DMZ) allows pre-authentication blind SQL injection. The fixed versions are MOVEit Transfer 2017 9.0.0.201, MOVEit DMZ 8.3.0.30, and MOVEit DMZ 8.2.0.20.

Exploit
  • EPSS 0.02%
  • Published 15.04.2016 15:59:01
  • Last modified 12.04.2025 10:46:40

Ipswitch MOVEit File Transfer (formerly DMZ) 8.1 and earlier, when configured to support file view on download, allows remote authenticated users to conduct cross-site scripting (XSS) attacks by uploading HTML files.

Exploit
  • EPSS 0.03%
  • Published 10.02.2016 15:59:04
  • Last modified 12.04.2025 10:46:40

Ipswitch MOVEit DMZ before 8.2 provides different error messages for authentication attempts depending on whether the user account exists, which allows remote attackers to enumerate usernames via a series of SOAP requests to machine.aspx.

  • EPSS 0.02%
  • Published 10.02.2016 15:59:01
  • Last modified 12.04.2025 10:46:40

The MOVEitISAPI service in Ipswitch MOVEit DMZ before 8.2 provides different error messages depending on whether a FileID exists, which allows remote authenticated users to enumerate FileIDs via the X-siLock-FileID parameter in a download action to M...

Exploit
  • EPSS 0.01%
  • Published 10.02.2016 15:59:00
  • Last modified 12.04.2025 10:46:40

The "Send as attachment" feature in Ipswitch MOVEit DMZ before 8.2 and MOVEit Mobile before 1.2.2 allow remote authenticated users to bypass authorization and read uploaded files via a valid FileID in the (1) serverFileIds parameter to mobile/sendMsg...