📦

file_transfer_appliance

Vendor: accellion

Actively Exploited 0 CISA KEV List
PoC / Exploits 1 Code Available
Total RCEs 4 Remote Access
Total CVEs 264 Total Indexed
Avg. EPSS 9.34% Exploit Prob.
Latest CVE CVE-2019-5623 Apr 29

Security Vulnerability Index

Page 1 / 27
9.8 CVSS

Accellion File Transfer Appliance version FTA_8_0_540 suffers from an instance of CWE-77: Improper Neutralization of Special Elements used in a Command ('Command Injection').

EPSS: 1.58%
9.8 CVSS

Accellion File Transfer Appliance version FTA_8_0_540 suffers from an instance of CWE-798: Use of Hard-coded Credentials.

EPSS: 1.10%
7.5 CVSS

Directory traversal vulnerability in the template function in function.inc in Accellion File Transfer Appliance devices before FTA_9_11_210 allows remote attackers to read arbitrary files via a .. (dot dot) in the statecode cookie.

EPSS: 56.57%
9.8 CVSS
CVE-2015-2857
RCE Exploit Found

Accellion File Transfer Appliance before FTA_9_11_210 allows remote attackers to execute arbitrary code via shell metacharacters in the oauth_token parameter.

EPSS: 84.18%
9.8 CVSS

An issue was discovered on Accellion FTA devices before FTA_9_12_180. Because mysql_real_escape_string is misused, seos/courier/communication_p2p.php allows SQL injection with the app_id parameter.

EPSS: 1.16%
6.1 CVSS

An issue was discovered on Accellion FTA devices before FTA_9_12_180. There is XSS in home/seos/courier/smtpg_add.html with the param parameter.

EPSS: 0.68%
10.0 CVSS

An issue was discovered on Accellion FTA devices before FTA_9_12_180. Because a regular expression (intended to match local https URLs) lacks an initial ^ character, courier/web/1000@/wmProgressval.html allows SSRF attacks with a file:///etc/passwd#https:// URL pattern.

EPSS: 1.90%
8.8 CVSS

An issue was discovered on Accellion FTA devices before FTA_9_12_180. By sending a POST request to home/seos/courier/web/wmProgressstat.html.php with an attacker domain in the acallow parameter, the device will respond with an Access-Control-Allow-Origin header allowing the attacker to have site access with a bypass of the Same Origin Policy.

EPSS: 0.51%
6.1 CVSS

An issue was discovered on Accellion FTA devices before FTA_9_12_180. There is XSS in home/seos/courier/user_add.html with the param parameter.

EPSS: 0.68%
6.1 CVSS

An issue was discovered on Accellion FTA devices before FTA_9_12_180. There is a home/seos/courier/login.html auth_params CRLF attack vector.

EPSS: 0.68%