Accellion

File Transfer Appliance

20 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
Exploit
  • EPSS 0.49%
  • Veröffentlicht 05.05.2017 18:29:00
  • Zuletzt bearbeitet 20.04.2025 01:37:25

An issue was discovered on Accellion FTA devices before FTA_9_12_180. The home/seos/courier/ldaptest.html POST parameter "filter" can be used for LDAP Injection.

Exploit
  • EPSS 0.25%
  • Veröffentlicht 05.05.2017 18:29:00
  • Zuletzt bearbeitet 20.04.2025 01:37:25

An issue was discovered on Accellion FTA devices before FTA_9_12_180. A report_error.php?year='payload SQL injection vector exists.

Exploit
  • EPSS 0.24%
  • Veröffentlicht 05.05.2017 18:29:00
  • Zuletzt bearbeitet 20.04.2025 01:37:25

An issue was discovered on Accellion FTA devices before FTA_9_12_180. There is a CRLF vulnerability in settings_global_text_edit.php allowing ?display=x%0Dnewline attacks.

Exploit
  • EPSS 1.04%
  • Veröffentlicht 05.05.2017 18:29:00
  • Zuletzt bearbeitet 20.04.2025 01:37:25

An issue was discovered on Accellion FTA devices before FTA_9_12_180. There is XSS in courier/1000@/index.html with the auth_params parameter. The device tries to use internal WAF filters to stop specific XSS Vulnerabilities. However, these can be by...

Exploit
  • EPSS 0.24%
  • Veröffentlicht 05.05.2017 18:29:00
  • Zuletzt bearbeitet 20.04.2025 01:37:25

An issue was discovered on Accellion FTA devices before FTA_9_12_180. courier/1000@/oauth/playground/callback.html allows XSS with a crafted URI.

Exploit
  • EPSS 10.24%
  • Veröffentlicht 05.05.2017 18:29:00
  • Zuletzt bearbeitet 20.04.2025 01:37:25

An issue was discovered on Accellion FTA devices before FTA_9_12_180. seos/1000/find.api allows Remote Code Execution with shell metacharacters in the method parameter.

Exploit
  • EPSS 0.04%
  • Veröffentlicht 07.05.2016 14:59:07
  • Zuletzt bearbeitet 12.04.2025 10:46:40

The Accellion File Transfer Appliance (FTA) before FTA_9_12_40 allows local users to add an SSH key to an arbitrary group, and consequently gain privileges, via unspecified vectors.

  • EPSS 0.99%
  • Veröffentlicht 07.05.2016 14:59:06
  • Zuletzt bearbeitet 12.04.2025 10:46:40

The Accellion File Transfer Appliance (FTA) before FTA_9_12_40 allows remote authenticated users to execute arbitrary commands by leveraging the YUM_CLIENT restricted-user role.

Exploit
  • EPSS 0.82%
  • Veröffentlicht 07.05.2016 14:59:04
  • Zuletzt bearbeitet 12.04.2025 10:46:40

SQL injection vulnerability in home/seos/courier/security_key2.api on the Accellion File Transfer Appliance (FTA) before FTA_9_12_40 allows remote attackers to execute arbitrary SQL commands via the client_id parameter.

Exploit
  • EPSS 0.3%
  • Veröffentlicht 07.05.2016 14:59:03
  • Zuletzt bearbeitet 12.04.2025 10:46:40

Multiple cross-site scripting (XSS) vulnerabilities on the Accellion File Transfer Appliance (FTA) before FTA_9_12_40 allow remote attackers to inject arbitrary web script or HTML via unspecified input to (1) getimageajax.php, (2) move_partition_fram...