Accellion Secure File Transfer Appliance before 80105 does not properly restrict access to sensitive commands and arguments that run with extra sudo privileges, which allows local administrators to gain privileges via (1) arbitrary arguments in the --filemove action in /usr/local/bin/admin.pl, or a hard link attack in (2) chmod or (3) a certain cp command.
Static code injection vulnerability in the administrative web interface in Accellion Secure File Transfer Appliance allows remote authenticated administrators to inject arbitrary shell commands by appending them to a request to update the SNMP public community string.
Directory traversal vulnerability in webclientuserguide.html in Accellion Secure File Transfer Appliance before 80105 allows remote attackers to read arbitrary files via a .. (dot dot) in the lang parameter.
Accellion Secure File Transfer Appliance before 80105 allows remote authenticated administrators to bypass the restricted shell and execute arbitrary commands via shell metacharacters to the ping command, as demonstrated by modifying the cli program.
Cross-site scripting (XSS) vulnerability in Accellion Secure File Transfer Appliance before 70296 allows remote attackers to inject arbitrary web script or HTML via the username parameter, which is not properly handled when the administrator views audit logs.
Accellion File Transfer Appliance version FTA80540 suffers from an instance of CWE-77: Improper Neutralization of Special Elements used in a Command ('Command Injection').
Accellion File Transfer Appliance version FTA80540 suffers from an instance of CWE-798: Use of Hard-coded Credentials.
Accellion File Transfer Appliance before FTA911210 allows remote attackers to execute arbitrary code via shell metacharacters in the oauthtoken parameter.
Directory traversal vulnerability in the template function in function.inc in Accellion File Transfer Appliance devices before FTA911210 allows remote attackers to read arbitrary files via a .. (dot dot) in the statecode cookie.
Multiple cross-site scripting (XSS) vulnerabilities on the Accellion File Transfer Appliance (FTA) before FTA91240 allow remote attackers to inject arbitrary web script or HTML via unspecified input to (1) getimageajax.php, (2) movepartitionframe.html, or (3) wmInfo.html.
SQL injection vulnerability in home/seos/courier/securitykey2.api on the Accellion File Transfer Appliance (FTA) before FTA91240 allows remote attackers to execute arbitrary SQL commands via the clientid parameter.
The Accellion File Transfer Appliance (FTA) before FTA91240 allows local users to add an SSH key to an arbitrary group, and consequently gain privileges, via unspecified vectors.
The Accellion File Transfer Appliance (FTA) before FTA91240 allows remote authenticated users to execute arbitrary commands by leveraging the YUMCLIENT restricted-user role.
An issue was discovered on Accellion FTA devices before FTA912180. By sending a POST request to home/seos/courier/web/wmProgressstat.html.php with an attacker domain in the acallow parameter, the device will respond with an Access-Control-Allow-Origin header allowing the attacker to have site access with a bypass of the Same Origin Policy.
An issue was discovered on Accellion FTA devices before FTA912180. There is XSS in home/seos/courier/useradd.html with the param parameter.
An issue was discovered on Accellion FTA devices before FTA912180. The home/seos/courier/ldaptest.html POST parameter "filter" can be used for LDAP Injection.
An issue was discovered on Accellion FTA devices before FTA912180. There is a home/seos/courier/login.html authparams CRLF attack vector.
An issue was discovered on Accellion FTA devices before FTA912180. Because a regular expression (intended to match local https URLs) lacks an initial ^ character, courier/web/1000@/wmProgressval.html allows SSRF attacks with a file:///etc/passwd#https:// URL pattern.
An issue was discovered on Accellion FTA devices before FTA912180. There is XSS in home/seos/courier/smtpgadd.html with the param parameter.
An issue was discovered on Accellion FTA devices before FTA912180. There is a CRLF vulnerability in settingsglobaltextedit.php allowing ?display=x%0Dnewline attacks.
An issue was discovered on Accellion FTA devices before FTA912180. Because mysqlrealescapestring is misused, seos/courier/communicationp2p.php allows SQL injection with the appid parameter.
An issue was discovered on Accellion FTA devices before FTA912180. A reporterror.php?year='payload SQL injection vector exists.
An issue was discovered on Accellion FTA devices before FTA912180. There is XSS in courier/1000@/index.html with the authparams parameter. The device tries to use internal WAF filters to stop specific XSS Vulnerabilities. However, these can be bypassed by using some modifications to the payloads, e.g., URL encoding.
An issue was discovered on Accellion FTA devices before FTA912180. courier/1000@/oauth/playground/callback.html allows XSS with a crafted URI.
An issue was discovered on Accellion FTA devices before FTA912180. seos/1000/find.api allows Remote Code Execution with shell metacharacters in the method parameter.