courier/1000@/apierroremail.html (aka "error reporting page") in Accellion File Transfer Appliance FTA70178, and possibly other versions before FTA70189, allows remote attackers to send spam e-mail via modified description and clientemail parameters.
Cross-site scripting (XSS) vulnerability in Accellion File Transfer FTA70135 allows remote attackers to inject arbitrary web script or HTML via the PATHINFO to courier/forgotpassword.html.