CVE-2009-4647: XSS
Cross-site scripting (XSS) vulnerability in Accellion Secure File Transfer Appliance before 70296 allows remote attackers to inject arbitrary web script or HTML via the username parameter, which is not properly handled when the administrator views audit logs.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2009-4647?
CVE-2009-4647 is classified as a medium severity cross-site scripting (XSS) vulnerability.
How do I fix CVE-2009-4647?
To fix CVE-2009-4647, update the Accellion Secure File Transfer Appliance to version 7_0_296 or later.
What software versions are affected by CVE-2009-4647?
CVE-2009-4647 affects versions prior to 7_0_296, specifically 7_0_178, 7_0_135, 7_0_259, and 7_0_189 of the Accellion Secure File Transfer Appliance.
What type of vulnerability is CVE-2009-4647?
CVE-2009-4647 is a cross-site scripting (XSS) vulnerability.
How does CVE-2009-4647 impact users?
CVE-2009-4647 allows remote attackers to inject arbitrary web script or HTML into the audit logs viewed by administrators.