CVE-2009-4645: Path Traversal
Directory traversal vulnerability in webclientuserguide.html in Accellion Secure File Transfer Appliance before 80105 allows remote attackers to read arbitrary files via a .. (dot dot) in the lang parameter.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2009-4645?
The severity of CVE-2009-4645 is considered high due to its potential to allow unauthorized access to sensitive files.
How do I fix CVE-2009-4645?
To fix CVE-2009-4645, update the Accellion Secure File Transfer Appliance to version 8_0_105 or later.
Which versions of Accellion Secure File Transfer Appliance are affected by CVE-2009-4645?
CVE-2009-4645 affects versions 7_0_135, 7_0_178, 7_0_189, 7_0_259, and 7_0_296 of the Accellion Secure File Transfer Appliance.
What kind of attack does CVE-2009-4645 enable?
CVE-2009-4645 enables a directory traversal attack that allows remote attackers to read arbitrary files on the server.
Is CVE-2009-4645 easy to exploit?
Yes, CVE-2009-4645 is relatively easy to exploit as it involves manipulating the 'lang' parameter to traverse directories.