7.2
CVSSv2

CVE-2009-4648

Published: 19/02/2010 Updated: 17/08/2017
CVSS v2 Base Score: 7.2 | Impact Score: 10 | Exploitability Score: 3.9
VMScore: 725
Vector: AV:L/AC:L/Au:N/C:C/I:C/A:C

Vulnerability Summary

Accellion Secure File Transfer Appliance prior to 8_0_105 does not properly restrict access to sensitive commands and arguments that run with extra sudo privileges, which allows local administrators to gain privileges via (1) arbitrary arguments in the --file_move action in /usr/local/bin/admin.pl, or a hard link attack in (2) chmod or (3) a certain cp command.

Vulnerable Product Search on Vulmon Subscribe to Product

accellion secure file transfer appliance 7_0_135

accellion secure file transfer appliance 7_0_178

accellion secure file transfer appliance 7_0_189

accellion secure file transfer appliance 7_0_259

accellion secure file transfer appliance 7_0_296

Exploits

source: wwwsecurityfocuscom/bid/38176/info Accellion File Transfer Appliance is prone to multiple remote vulnerabilities, including: - Multiple privilege-escalation issues - A directory-traversal issue - An HTML-injection issue - A remote command-injection issue An attacker may leverage these issues to execute arbitrary script code w ...