CVE-2017-8790
- EPSS 0.49%
- Published 05.05.2017 18:29:00
- Last modified 20.04.2025 01:37:25
An issue was discovered on Accellion FTA devices before FTA_9_12_180. The home/seos/courier/ldaptest.html POST parameter "filter" can be used for LDAP Injection.
CVE-2017-8789
- EPSS 0.25%
- Published 05.05.2017 18:29:00
- Last modified 20.04.2025 01:37:25
An issue was discovered on Accellion FTA devices before FTA_9_12_180. A report_error.php?year='payload SQL injection vector exists.
CVE-2017-8788
- EPSS 0.24%
- Published 05.05.2017 18:29:00
- Last modified 20.04.2025 01:37:25
An issue was discovered on Accellion FTA devices before FTA_9_12_180. There is a CRLF vulnerability in settings_global_text_edit.php allowing ?display=x%0Dnewline attacks.
CVE-2017-8760
- EPSS 1.04%
- Published 05.05.2017 18:29:00
- Last modified 20.04.2025 01:37:25
An issue was discovered on Accellion FTA devices before FTA_9_12_180. There is XSS in courier/1000@/index.html with the auth_params parameter. The device tries to use internal WAF filters to stop specific XSS Vulnerabilities. However, these can be by...
CVE-2017-8304
- EPSS 0.24%
- Published 05.05.2017 18:29:00
- Last modified 20.04.2025 01:37:25
An issue was discovered on Accellion FTA devices before FTA_9_12_180. courier/1000@/oauth/playground/callback.html allows XSS with a crafted URI.
CVE-2017-8303
- EPSS 10.24%
- Published 05.05.2017 18:29:00
- Last modified 20.04.2025 01:37:25
An issue was discovered on Accellion FTA devices before FTA_9_12_180. seos/1000/find.api allows Remote Code Execution with shell metacharacters in the method parameter.
CVE-2016-2353
- EPSS 0.04%
- Published 07.05.2016 14:59:07
- Last modified 12.04.2025 10:46:40
The Accellion File Transfer Appliance (FTA) before FTA_9_12_40 allows local users to add an SSH key to an arbitrary group, and consequently gain privileges, via unspecified vectors.
CVE-2016-2352
- EPSS 0.99%
- Published 07.05.2016 14:59:06
- Last modified 12.04.2025 10:46:40
The Accellion File Transfer Appliance (FTA) before FTA_9_12_40 allows remote authenticated users to execute arbitrary commands by leveraging the YUM_CLIENT restricted-user role.
CVE-2016-2351
- EPSS 0.82%
- Published 07.05.2016 14:59:04
- Last modified 12.04.2025 10:46:40
SQL injection vulnerability in home/seos/courier/security_key2.api on the Accellion File Transfer Appliance (FTA) before FTA_9_12_40 allows remote attackers to execute arbitrary SQL commands via the client_id parameter.
CVE-2016-2350
- EPSS 0.3%
- Published 07.05.2016 14:59:03
- Last modified 12.04.2025 10:46:40
Multiple cross-site scripting (XSS) vulnerabilities on the Accellion File Transfer Appliance (FTA) before FTA_9_12_40 allow remote attackers to inject arbitrary web script or HTML via unspecified input to (1) getimageajax.php, (2) move_partition_fram...