Loading
Directory traversal vulnerability in the template function in function.inc in Accellion File Transfer Appliance devices before FTA_9_11_210 allows remote attackers to read arbitrary files via a .. (dot dot) in the statecode cookie.
Use CWE-22, Accellion vendor hub and File Transfer Appliance product page to widen CVE-2015-2856 into its surrounding weakness, vendor, and product context.
Compare it with CVE-2017-8794, CVE-2019-5623 and CVE-2019-5622 for nearby disclosures in the same product family.