PT-2017-6615 · Accellion · Accellion File Transfer Appliance
Hdm
·
Published
2017-10-10
·
Updated
2017-10-23
·
CVE-2015-2856
CVSS v2.0
5.0
Medium
| Vector | AV:N/AC:L/Au:N/C:P/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
Accellion File Transfer Appliance devices versions prior to FTA 9 11 210
Description
A directory traversal issue exists in the template function in function.inc, allowing remote attackers to read arbitrary files by including a .. (dot dot) in the
statecode cookie.Recommendations
For versions prior to FTA 9 11 210, update to FTA 9 11 210 or later to resolve the issue.
Exploit
Fix
Path traversal
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Accellion File Transfer Appliance