Multiple cross-site scripting (XSS) vulnerabilities on the Accellion File Transfer Appliance (FTA) before FTA91240 allow remote attackers to inject arbitrary web script or HTML via unspecified input to (1) getimageajax.php, (2) movepartitionframe.html, or (3) wmInfo.html.
SQL injection vulnerability in home/seos/courier/securitykey2.api on the Accellion File Transfer Appliance (FTA) before FTA91240 allows remote attackers to execute arbitrary SQL commands via the clientid parameter.
The Accellion File Transfer Appliance (FTA) before FTA91240 allows local users to add an SSH key to an arbitrary group, and consequently gain privileges, via unspecified vectors.
The Accellion File Transfer Appliance (FTA) before FTA91240 allows remote authenticated users to execute arbitrary commands by leveraging the YUMCLIENT restricted-user role.