CVE-2015-7677
10.02.2016, 15:59
The MOVEitISAPI service in Ipswitch MOVEit DMZ before 8.2 provides different error messages depending on whether a FileID exists, which allows remote authenticated users to enumerate FileIDs via the X-siLock-FileID parameter in a download action to MOVEitISAPI/MOVEitISAPI.dll.Enginsight
Vendor | Product | Version |
---|---|---|
ipswitch | moveit_dmz | 𝑥 ≤ 8.1 |
𝑥
= Vulnerable software versions
Common Weakness Enumeration
References