Show filters
28 Total Results
Displaying 1-10 of 28
Sort by:
Attacker Value
Unknown

CVE-2019-10219

Disclosure Date: November 08, 2019 (last updated November 08, 2023)
A vulnerability was found in Hibernate-Validator. The SafeHtml validator annotation fails to properly sanitize payloads consisting of potentially malicious code in HTML comments and instructions. This vulnerability can result in an XSS attack.
Attacker Value
Unknown

CVE-2015-2856

Disclosure Date: October 10, 2017 (last updated November 26, 2024)
Directory traversal vulnerability in the template function in function.inc in Accellion File Transfer Appliance devices before FTA_9_11_210 allows remote attackers to read arbitrary files via a .. (dot dot) in the statecode cookie.
0
Attacker Value
Unknown

CVE-2015-2857

Disclosure Date: August 22, 2017 (last updated November 26, 2024)
Accellion File Transfer Appliance before FTA_9_11_210 allows remote attackers to execute arbitrary code via shell metacharacters in the oauth_token parameter.
Attacker Value
Unknown

CVE-2017-8794

Disclosure Date: May 05, 2017 (last updated November 26, 2024)
An issue was discovered on Accellion FTA devices before FTA_9_12_180. Because a regular expression (intended to match local https URLs) lacks an initial ^ character, courier/web/1000@/wmProgressval.html allows SSRF attacks with a file:///etc/passwd#https:// URL pattern.
0
Attacker Value
Unknown

CVE-2017-8793

Disclosure Date: May 05, 2017 (last updated November 26, 2024)
An issue was discovered on Accellion FTA devices before FTA_9_12_180. By sending a POST request to home/seos/courier/web/wmProgressstat.html.php with an attacker domain in the acallow parameter, the device will respond with an Access-Control-Allow-Origin header allowing the attacker to have site access with a bypass of the Same Origin Policy.
0
Attacker Value
Unknown

CVE-2017-8789

Disclosure Date: May 05, 2017 (last updated November 26, 2024)
An issue was discovered on Accellion FTA devices before FTA_9_12_180. A report_error.php?year='payload SQL injection vector exists.
0
Attacker Value
Unknown

CVE-2017-8795

Disclosure Date: May 05, 2017 (last updated November 26, 2024)
An issue was discovered on Accellion FTA devices before FTA_9_12_180. There is XSS in home/seos/courier/smtpg_add.html with the param parameter.
0
Attacker Value
Unknown

CVE-2017-8788

Disclosure Date: May 05, 2017 (last updated November 26, 2024)
An issue was discovered on Accellion FTA devices before FTA_9_12_180. There is a CRLF vulnerability in settings_global_text_edit.php allowing ?display=x%0Dnewline attacks.
0
Attacker Value
Unknown

CVE-2017-8792

Disclosure Date: May 05, 2017 (last updated November 26, 2024)
An issue was discovered on Accellion FTA devices before FTA_9_12_180. There is XSS in home/seos/courier/user_add.html with the param parameter.
0
Attacker Value
Unknown

CVE-2017-8791

Disclosure Date: May 05, 2017 (last updated November 26, 2024)
An issue was discovered on Accellion FTA devices before FTA_9_12_180. There is a home/seos/courier/login.html auth_params CRLF attack vector.
0