CVE-2015-2857
CRITICALAccellion File Transfer Appliance < 9_11_200 - Remote Code Execution via oauth_token Parameter
Title source: llmExploitation Summary
EIP tracks 2 public exploits for CVE-2015-2857.
PoCs published by Metasploit, hdm, including Metasploit module exploits/linux/http/accellion_fta_getstatus_oauth.
AI-analyzed exploit summary This Metasploit module exploits a command injection vulnerability in Accellion FTA by injecting shell metacharacters into the 'oauth_token' parameter, leading to remote code execution. The exploit targets the '/tws/getStatus' endpoint and confirms vulnerability via a check method.
Description
Accellion File Transfer Appliance before FTA_9_11_210 allows remote attackers to execute arbitrary code via shell metacharacters in the oauth_token parameter.
Exploits (2)
This Metasploit module exploits a command injection vulnerability in Accellion FTA by injecting shell metacharacters into the 'oauth_token' parameter, leading to remote code execution. The exploit targets the '/tws/getStatus' endpoint and confirms vulnerability via a check method.
This Metasploit module exploits a command injection vulnerability in Accellion FTA by injecting shell metacharacters into the 'oauth_token' parameter, which is passed to a system() call. The exploit targets the '/tws/getStatus' endpoint and achieves remote code execution.
References (4)
Scores
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H