Description
courier/1000@/api_error_email.html (aka "error reporting page") in Accellion File Transfer Appliance FTA_7_0_178, and possibly other versions before FTA_7_0_189, allows remote attackers to send spam e-mail via modified description and client_email parameters.
Affected products
- Accellion / secure_file_transfer_appliance7_0_178
- Accellion / secure_file_transfer_appliance7_0_135 – 7_0_135
References
- MISChttp://www.securityfocus.com/bid/31178
- MISChttp://www.securitytracker.com/id?1020870
- MISChttp://osvdb.org/48242
- MISChttp://zebux.free.fr/pub/Advisory/Advisory_Accellion_SPAM_Engine_Vulnerability_200808.txt
- VENDOR_ADVISORYhttp://secunia.com/advisories/31848
- MISChttps://exchange.xforce.ibmcloud.com/vulnerabilities/45159