Vulnerability   
Search   
    Search 324607 CVE descriptions
and 145615 test descriptions,
access 10,000+ cross references.
Tests   CVE   All  

Test ID:1.3.6.1.4.1.25623.1.0.106031
Category:Web application abuses
Title:Accellion FTA File Disclosure Vulnerability
Summary:Accellion FTA is prone to a file disclosure vulnerability
Description:Summary:
Accellion FTA is prone to a file disclosure vulnerability

Vulnerability Insight:
The vulnerability is triggered when a user-provided 'statecode'
cookie parameter is appended to a file path that is processed as a HTML template. By prepending this
cookie with directory traversal sequence and appending a NULL byte, any file readable by the web user
can be exposed.

Vulnerability Impact:
An attacker can read sensitive files, including the system
configuration and files uploaded to the appliance by users.

Affected Software/OS:
Accellion FTA Version 9.11.200 and prior.

Solution:
Upgrade to version 9.11.210 or later.

CVSS Score:
5.0

CVSS Vector:
AV:N/AC:L/Au:N/C:P/I:N/A:N

Cross-Ref: Common Vulnerability Exposure (CVE) ID: CVE-2015-2856
https://www.rapid7.com/db/modules/auxiliary/scanner/http/accellion_fta_statecode_file_read
CopyrightCopyright (C) 2015 Greenbone Networks GmbH

This is only one of 145615 vulnerability tests in our test suite. Find out more about running a complete security audit.

To run a free test of this vulnerability against your system, register below.




© 1998-2025 E-Soft Inc. All rights reserved.