8119Third-party advisory
http://securityreason.com/securityalert/8119 CVE-2010-4566
Citrix Access Gateway - Command Injection
Record summary
CVE-2010-4566 has a selected CVSS score of 9.3; EIP currently links 3 catalogued exploits.
Description
The web authentication form in the NT4 authentication component in Citrix Access Gateway Enterprise Edition 9.2-49.8 and earlier, and the NTLM authentication component in Access Gateway Standard and Advanced Editions before Access Gateway 5.0, allows attackers to execute arbitrary commands via shell metacharacters in the password field.
Description source: CVE List
Exploitation context
Available material
- Catalogued exploits
- 3
Proofs of concept
3Catalogued exploits
ExploitDBCitrix Access Gateway - Command InjectionExploitDB exploitby George D. GalNot analyzed1 file
ExploitDBCitrix Access Gateway - Command Execution (Metasploit)ExploitDB exploitby MetasploitNot analyzed1 file
MetasploitCitrix Access Gateway Command ExecutionMetasploit exploitby Erwin Paternotte +1 moreNot analyzed1 file
References
7support.citrix.comConfirmation
http://support.citrix.com/article/CTX127613 16916exploit
http://www.exploit-db.com/exploits/16916 70099vdb entry
http://www.osvdb.org/70099 1024893vdb entry
http://www.securitytracker.com/id?1024893 vsecurity.com
http://www.vsecurity.com/resources/advisory/20101221-1 nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2010-4566