The MOVEitISAPI service in Ipswitch MOVEit DMZ prior to 8.2 provides different error messages depending on whether a FileID exists, which allows remote authenticated users to enumerate FileIDs via the X-siLock-FileID parameter in a download action to MOVEitISAPI/MOVEitISAPI.dll.
Vulnerable Product | Search on Vulmon | Subscribe to Product |
---|---|---|
ipswitch moveit dmz |