CVE-2009-3758
Citrix XenCenterWeb - SQL Injection via login.php Username Parameter
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2009-3758. PoCs published by Secure Network.
AI-analyzed exploit summary This advisory details multiple vulnerabilities in Citrix XenCenterWeb, including XSS, CSRF, SQL injection, and remote command execution. It provides technical explanations and proof-of-concept URLs for each vulnerability.
Description
SQL injection vulnerability in login.php in sample code in the XenServer Resource Kit in Citrix XenCenterWeb allows remote attackers to execute arbitrary SQL commands via the username parameter. NOTE: some of these details are obtained from third party information.
Exploits (1)
This advisory details multiple vulnerabilities in Citrix XenCenterWeb, including XSS, CSRF, SQL injection, and remote command execution. It provides technical explanations and proof-of-concept URLs for each vulnerability.