CVE-2015-2857

Severity CVSS v4.0:
Pending analysis
Type:
CWE-77 Command Injection
Publication date:
22/08/2017
Last modified:
20/04/2025

Description

Accellion File Transfer Appliance before FTA_9_11_210 allows remote attackers to execute arbitrary code via shell metacharacters in the oauth_token parameter.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:accellion:file_transfer_appliance:*:*:*:*:*:*:*:* 9_11_200 (including)