High severity7.5NVD Advisory· Published Jan 21, 2019· Updated Jun 17, 2026
CVE-2019-6500
CVE-2019-6500
Description
In Axway File Transfer Direct 2.7.1, an unauthenticated Directory Traversal vulnerability can be exploited by issuing a specially crafted HTTP GET request with %2e instead of '.' characters, as demonstrated by an initial /h2hdocumentation//%2e%2e/ substring.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
2- cpe:2.3:a:axway:file_tranfer_direct:2.7.1:*:*:*:*:*:*:*
- Range: <2.7.1
Patches
Vulnerability mechanics
References
2- github.com/inf0seq/inf0seq.github.io/blob/master/_posts/2019-01-20-Directory-Traversal-in-Axway-File-Transfer-Direct.mdnvdExploitThird Party Advisory
- inf0seq.github.io/cve/2019/01/20/Directory-Traversal-in-Axway-File-Transfer-Direct.htmlnvdExploitThird Party Advisory
News mentions
0No linked articles in our index yet.