Record summary

CVE-2010-4566 has a selected CVSS score of 9.3; EIP currently links 3 catalogued exploits.

Description

The web authentication form in the NT4 authentication component in Citrix Access Gateway Enterprise Edition 9.2-49.8 and earlier, and the NTLM authentication component in Access Gateway Standard and Advanced Editions before Access Gateway 5.0, allows attackers to execute arbitrary commands via shell metacharacters in the password field.

Description source: CVE List

Exploitation context

Available material

Catalogued exploits
3

Proofs of concept

3

Catalogued exploits

ExploitDBCitrix Access Gateway - Command InjectionExploitDB exploitby George D. GalNot analyzed1 file
ExploitDB

PoC details
ExploitDBCitrix Access Gateway - Command Execution (Metasploit)ExploitDB exploitby MetasploitNot analyzed1 file
ExploitDB

PoC details
MetasploitCitrix Access Gateway Command ExecutionMetasploit exploitby Erwin Paternotte +1 moreNot analyzed1 file

Ruby

Metasploit

PoC details

References

7