CVE-2016-9500

Severity CVSS v4.0:
Pending analysis
Type:
CWE-79 Cross-Site Scripting (XSS)
Publication date:
13/07/2018
Last modified:
09/10/2019

Description

Accellion FTP server prior to version FTA_9_12_220 uses the Accusoft Prizm Content flash component, which contains multiple parameters (customTabCategoryName, customButton1Image) that are vulnerable to cross-site scripting.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:accellion:ftp_server:*:*:*:*:*:*:*:* fta_9_12_220 (excluding)