CVE-2016-9500: The Accellion FTP server prior to version FTA_9_12_220 is vulnerable to informaiton exposure
Accellion FTP server prior to version FTA912220 uses the Accusoft Prizm Content flash component, which contains multiple parameters (customTabCategoryName, customButton1Image) that are vulnerable to cross-site scripting.
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is CVE-2016-9500?
CVE-2016-9500 is a vulnerability found in Accellion FTP server prior to version FTA_9_12_220.
What is the severity of CVE-2016-9500?
CVE-2016-9500 has a severity value of 6.1, which is considered medium.
How does CVE-2016-9500 affect Accellion FTP server?
CVE-2016-9500 affects Accellion FTP server versions prior to FTA_9_12_220 by making it susceptible to cross-site scripting due to vulnerabilities in the Accusoft Prizm Content flash component.
What is Accusoft Prizm Content flash component?
Accusoft Prizm Content flash component is a component used by Accellion FTP server that contains multiple parameters which are vulnerable to cross-site scripting.
How can I fix CVE-2016-9500?
To fix CVE-2016-9500, it is recommended to update Accellion FTP server to version FTA_9_12_220 or later to patch the vulnerabilities in the Accusoft Prizm Content flash component.