Accellion FTP server prior to version FTA_9_12_220 uses the Accusoft Prizm Content flash component, which contains multiple parameters (customTabCategoryName, customButton1Image) that are vulnerable to cross-site scripting.
Solution:
The product receives input from an upstream component, but it does not neutralize or incorrectly neutralizes special characters such as "<", ">", and "&" that could be interpreted as web-scripting elements when they are sent to a downstream component that processes web pages.
The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users.
Link | Tags |
---|---|
https://www.qualys.com/2016/12/06/qsa-2016-12-06/qsa-2016-12-06.pdf | third party advisory exploit |
https://www.securityfocus.com/bid/96154 | third party advisory vdb entry |
https://www.kb.cert.org/vuls/id/745607 | third party advisory us government resource |