Accellion Secure File Transfer Appliance before 80105 allows remote authenticated administrators to bypass the restricted shell and execute arbitrary commands via shell metacharacters to the ping command, as demonstrated by modifying the cli program.
Directory traversal vulnerability in webclientuserguide.html in Accellion Secure File Transfer Appliance before 80105 allows remote attackers to read arbitrary files via a .. (dot dot) in the lang parameter.
Accellion Secure File Transfer Appliance before 80105 does not properly restrict access to sensitive commands and arguments that run with extra sudo privileges, which allows local administrators to gain privileges via (1) arbitrary arguments in the --filemove action in /usr/local/bin/admin.pl, or a hard link attack in (2) chmod or (3) a certain cp command.