CVE-2016-4945
MEDIUM EXPLOITEDCitrix Netscaler Gateway 11.0 Firmware < 65.35 - XSS
Title source: ruleDescription
Cross-site scripting (XSS) vulnerability in vpn/js/gateway_login_form_view.js in Citrix NetScaler Gateway 11.0 before Build 66.11 allows remote attackers to inject arbitrary web script or HTML via the NSC_TMAC cookie.
References (5)
Scores
CVSS v3
6.1
EPSS
0.0062
EPSS Percentile
69.6%
Attack Vector
NETWORK
CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
Exploitation Intel
VulnCheck KEV
2024-07-16
Classification
CWE
CWE-79
Status
draft
Affected Products (1)
citrix/netscaler_gateway_11.0_firmware
< 65.35
Timeline
Published
Jun 01, 2016
Tracked Since
Feb 18, 2026