Vulmon
Recent Vulnerabilities
Research Posts
Trends
Blog
About
Contact
Vulmon Alerts
By Relevance
By Risk Score
By Publish Date
accellion vulnerabilities and exploits
(subscribe to this query)
8.8
CVSSv3
CVE-2021-31586
Accellion Kiteworks prior to 7.4.0 allows an authenticated user to perform SQL Injection via LDAPGroup Search.
Accellion Kiteworks
9.8
CVSSv3
CVE-2021-27101
Accellion FTA 9_12_370 and previous versions is affected by SQL injection via a crafted Host header in a request to document_root.html. The fixed version is FTA_9_12_380 and later.
Accellion Fta
1 Article
7.8
CVSSv3
CVE-2021-27102
Accellion FTA 9_12_411 and previous versions is affected by OS command execution via a local web service call. The fixed version is FTA_9_12_416 and later.
Accellion Fta
1 Github repository
1 Article
9.8
CVSSv3
CVE-2021-27104
Accellion FTA 9_12_370 and previous versions is affected by OS command execution via a crafted POST request to various admin endpoints. The fixed version is FTA_9_12_380 and later.
Accellion Fta
3 Github repositories
1 Article
7.8
CVSSv3
CVE-2016-5662
Accellion Kiteworks appliances before kw2016.03.00 use setuid-root permissions for /opt/bin/cli, which allows local users to gain privileges via unspecified vectors.
Accellion Kiteworks Appliance
6.1
CVSSv3
CVE-2016-5663
Multiple cross-site scripting (XSS) vulnerabilities in oauth_callback.php on Accellion Kiteworks appliances before kw2016.03.00 allow remote malicious users to inject arbitrary web script or HTML via the (1) code, (2) error, or (3) error_description parameter.
Accellion Kiteworks Appliance
4.3
CVSSv3
CVE-2016-5664
Directory traversal vulnerability on Accellion Kiteworks appliances before kw2016.03.00 allows remote malicious users to read files via a crafted URI.
Accellion Kiteworks Appliance
6.1
CVSSv3
CVE-2016-9500
Accellion FTP server prior to version FTA_9_12_220 uses the Accusoft Prizm Content flash component, which contains multiple parameters (customTabCategoryName, customButton1Image) that are vulnerable to cross-site scripting.
Accellion Ftp Server
5.3
CVSSv3
CVE-2016-9499
Accellion FTP server prior to version FTA_9_12_220 only returns the username in the server response if the username is invalid. An attacker may use this information to determine valid user accounts and enumerate them.
Accellion Ftp Server
7.5
CVSSv3
CVE-2015-2856
Directory traversal vulnerability in the template function in function.inc in Accellion File Transfer Appliance devices before FTA_9_11_210 allows remote malicious users to read arbitrary files via a .. (dot dot) in the statecode cookie.
Accellion File Transfer Appliance
CVSSv3
CVSSv2
CVSSv3
VMScore
Recommendations:
cross-site request forgery
CVE-2024-34351
CVE-2024-1076
CVE-2024-25522
CVE-2024-34547
CVE-2024-4644
unauthorized
remote
CVE-2024-4671
Vulnerability Notification Service
You don’t have to wait for vulnerability scanning results
Get Started
« PREV
1
2
3
4
5
NEXT »