CVE-2015-2682

Citrix Command Center <5.1-5.2 - Info Disclosure

Title source: llm
STIX 2.1

Exploitation Summary

EIP tracks 1 public exploit for CVE-2015-2682. PoCs published by Han Sahin.

AI-analyzed exploit summary This writeup describes an information leak vulnerability in Citrix Command Center where unauthenticated attackers can download configuration files containing encoded credentials. The passwords can be trivially decoded, allowing privileged access to managed devices.

Description

Citrix Command Center before 5.1 Build 35.4 and 5.2 before Build 42.7 allows remote attackers to obtain credentials via a direct request to conf/securitydbData.xml.

Exploits (1)

exploitdb WRITEUP
by Han Sahin · textwebappsxml
https://www.exploit-db.com/exploits/36441

This writeup describes an information leak vulnerability in Citrix Command Center where unauthenticated attackers can download configuration files containing encoded credentials. The passwords can be trivially decoded, allowing privileged access to managed devices.

Classification
Writeup 100%
Attack Type
Info Leak
Complexity
Trivial
Reliability
Reliable
Target: Citrix Command Center 5.1 build 33.3 (and possibly others)
No auth needed
Prerequisites: Network access to the Citrix Command Center web interface
devstral-2 · analyzed Feb 16, 2026 Full analysis →

References (7)

Core 7
Core References
Mailing List, Third Party Advisory mailing-list x_refsource_fulldisc
http://seclists.org/fulldisclosure/2015/Mar/126
Third Party Advisory, VDB Entry exploit x_refsource_exploit-db
https://www.exploit-db.com/exploits/36441/
Vendor Advisory x_refsource_confirm
http://support.citrix.com/article/CTX200584
Third Party Advisory, VDB Entry vdb-entry x_refsource_sectrack
http://www.securitytracker.com/id/1031993
Third Party Advisory, VDB Entry vdb-entry x_refsource_bid
http://www.securityfocus.com/bid/73309

Scores

EPSS 0.1079
EPSS Percentile 95.3%

Details

CWE
CWE-17
Status published
Products (2)
citrix/command_center 5.1
citrix/command_center 5.2
Published Mar 26, 2015
Tracked Since Feb 18, 2026