Unrated severityNVD Advisory· Published Feb 19, 2010· Updated Apr 29, 2026
CVE-2009-4647
CVE-2009-4647
Description
Cross-site scripting (XSS) vulnerability in Accellion Secure File Transfer Appliance before 7_0_296 allows remote attackers to inject arbitrary web script or HTML via the username parameter, which is not properly handled when the administrator views audit logs.
Affected products
4cpe:2.3:h:accellion:secure_file_transfer_appliance:7_0_135:*:*:*:*:*:*:*+ 3 more
- cpe:2.3:h:accellion:secure_file_transfer_appliance:7_0_135:*:*:*:*:*:*:*
- cpe:2.3:h:accellion:secure_file_transfer_appliance:7_0_178:*:*:*:*:*:*:*
- cpe:2.3:h:accellion:secure_file_transfer_appliance:7_0_189:*:*:*:*:*:*:*
- cpe:2.3:h:accellion:secure_file_transfer_appliance:7_0_259:*:*:*:*:*:*:*
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
4- www.portcullis-security.com/339.phpnvdExploit
- www.securityfocus.com/bid/38176nvdExploit
- secunia.com/advisories/38522nvdVendor Advisory
- exchange.xforce.ibmcloud.com/vulnerabilities/56247nvd
News mentions
0No linked articles in our index yet.