CVE-2016-9499
The Accellion FTP server prior to version FTA_9_12_220 is vulnerable to cross-site scripting.
Severity Score
5.3
*CVSS v3
Exploit Likelihood
*EPSS
Affected Versions
*CPE
Public Exploits
1
*Multiple Sources
Exploited in Wild
-
*KEV
Decision
-
*SSVC
Descriptions
Accellion FTP server prior to version FTA_9_12_220 only returns the username in the server response if the username is invalid. An attacker may use this information to determine valid user accounts and enumerate them.
El servidor Accellion FTP en versiones anteriores a FTA_9_12_220 solo devuelve el nombre de usuario en la respuesta del servidor si el nombre de usuario no es válido. Un atacante podría usar esta información para determinar cuentas de usuario válidas y enumerarlas.
*Credits:
Thanks to Ashish Kamble for reporting this vulnerability.
CVSS Scores
Attack Vector
Attack Complexity
Privileges Required
User Interaction
Scope
Confidentiality
Integrity
Availability
Attack Vector
Attack Complexity
Authentication
Confidentiality
Integrity
Availability
* Common Vulnerability Scoring System
SSVC
- Decision:-
Exploitation
Automatable
Tech. Impact
* Organization's Worst-case Scenario
Timeline
- 2016-11-21 CVE Reserved
- 2018-07-13 CVE Published
- 2023-12-04 EPSS Updated
- 2024-08-06 CVE Updated
- 2024-08-06 First Exploit
- ---------- Exploited in Wild
- ---------- KEV Due Date
CWE
- CWE-200: Exposure of Sensitive Information to an Unauthorized Actor
- CWE-204: Observable Response Discrepancy
CAPEC
References (3)
URL | Tag | Source |
---|---|---|
https://www.kb.cert.org/vuls/id/745607 | Third Party Advisory | |
https://www.securityfocus.com/bid/96154 | Third Party Advisory |
URL | Date | SRC |
---|---|---|
https://www.qualys.com/2016/12/06/qsa-2016-12-06/qsa-2016-12-06.pdf | 2024-08-06 |
URL | Date | SRC |
---|
URL | Date | SRC |
---|
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Accellion Search vendor "Accellion" | Ftp Server Search vendor "Accellion" for product "Ftp Server" | < fta_9_12_220 Search vendor "Accellion" for product "Ftp Server" and version " < fta_9_12_220" | - |
Affected
|