Description
Directory traversal vulnerability in web_client_user_guide.html in Accellion Secure File Transfer Appliance before 8_0_105 allows remote attackers to read arbitrary files via a .. (dot dot) in the lang parameter.
Affected products
- Accellion / secure_file_transfer_appliance7_0_135 – 7_0_135
- Accellion / secure_file_transfer_appliance7_0_178 – 7_0_178
- Accellion / secure_file_transfer_appliance7_0_189 – 7_0_189
- Accellion / secure_file_transfer_appliance7_0_259 – 7_0_259
- Accellion / secure_file_transfer_appliance7_0_296 – 7_0_296