CVE-2016-2350: XSS
Multiple cross-site scripting (XSS) vulnerabilities on the Accellion File Transfer Appliance (FTA) before FTA91240 allow remote attackers to inject arbitrary web script or HTML via unspecified input to (1) getimageajax.php, (2) movepartitionframe.html, or (3) wmInfo.html.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2016-2350?
CVE-2016-2350 is considered a moderate severity vulnerability due to its potential to allow remote attackers to execute arbitrary web scripts via XSS.
How do I fix CVE-2016-2350?
To fix CVE-2016-2350, it is recommended to upgrade the Accellion File Transfer Appliance to version FTA_9_12_40 or later.
What type of vulnerabilities are described in CVE-2016-2350?
CVE-2016-2350 describes multiple cross-site scripting (XSS) vulnerabilities that can lead to unauthorized script execution.
Which components of Accellion File Transfer Appliance are affected by CVE-2016-2350?
CVE-2016-2350 affects components including getimageajax.php, move_partition_frame.html, and wmInfo.html.
Can CVE-2016-2350 be exploited remotely?
Yes, CVE-2016-2350 can be exploited remotely by attackers through malicious input to the affected files.