Accellion FTA 9_12_370

CPE Details

Accellion FTA 9_12_370
9_12_370
2021-02-17
17h49 +00:00
2021-02-17
17h49 +00:00
Alerte pour un CPE
Restez informé de toutes modifications pour un CPE spécifique.
Gestion des notifications

CPE Name: cpe:2.3:a:accellion:fta:9_12_370:*:*:*:*:*:*:*

Informations

Vendor

accellion

Product

fta

Version

9_12_370

Related CVE

Open and find in CVE List

CVE ID Publié Description Score Gravité
CVE-2021-27730 2021-03-02 00h03 +00:00 Accellion FTA 9_12_432 and earlier is affected by argument injection via a crafted POST request to an admin endpoint. The fixed version is FTA_9_12_444 and later.
9.8
Critique
CVE-2021-27731 2021-03-02 00h00 +00:00 Accellion FTA 9_12_432 and earlier is affected by stored XSS via a crafted POST request to a user endpoint. The fixed version is FTA_9_12_444 and later.
6.1
Moyen
CVE-2021-27104 2021-02-16 20h16 +00:00 Accellion FTA 9_12_370 and earlier is affected by OS command execution via a crafted POST request to various admin endpoints. The fixed version is FTA_9_12_380 and later.
9.8
Critique
CVE-2021-27103 2021-02-16 20h12 +00:00 Accellion FTA 9_12_411 and earlier is affected by SSRF via a crafted POST request to wmProgressstat.html. The fixed version is FTA_9_12_416 and later.
9.8
Critique
CVE-2021-27102 2021-02-16 20h07 +00:00 Accellion FTA 9_12_411 and earlier is affected by OS command execution via a local web service call. The fixed version is FTA_9_12_416 and later.
7.8
Haute
CVE-2021-27101 2021-02-16 20h02 +00:00 Accellion FTA 9_12_370 and earlier is affected by SQL injection via a crafted Host header in a request to document_root.html. The fixed version is FTA_9_12_380 and later.
9.8
Critique