CVE-2017-8789: SQL Injection
Published May 5, 2017
·Updated
An issue was discovered on Accellion FTA devices before FTA912180. A reporterror.php?year='payload SQL injection vector exists.
Affected Software
1 affected component
Accellion File Transfer Appliance<=9_12_40
Event History
May 5, 2017
CVE Published
via MITRE·06:00 PM
Data Sourced
via MITRE·06:00 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2017-8789?
CVE-2017-8789 is considered to be of medium severity due to its SQL injection vulnerability that can lead to unauthorized access to the database.
2
How do I fix CVE-2017-8789?
To mitigate CVE-2017-8789, you should update the Accellion FTA device to version FTA_9_12_180 or later.
3
What type of vulnerability is CVE-2017-8789?
CVE-2017-8789 is an SQL injection vulnerability that can be exploited through the report_error.php script.
4
Which versions of Accellion File Transfer Appliance are affected by CVE-2017-8789?
Accellion File Transfer Appliance versions before FTA_9_12_180 are affected by CVE-2017-8789.
5
What can attackers do with CVE-2017-8789?
Attackers can exploit CVE-2017-8789 to execute arbitrary SQL commands that may compromise sensitive data stored in the database.