9.3
CVSSv2

CVE-2011-2882

Published: 21/07/2011 Updated: 22/09/2011
CVSS v2 Base Score: 9.3 | Impact Score: 10 | Exploitability Score: 8.6
VMScore: 935
Vector: AV:N/AC:M/Au:N/C:C/I:C/A:C

Vulnerability Summary

Stack-based buffer overflow in the NSEPA.NsepaCtrl.1 ActiveX control in nsepa.ocx in Citrix Access Gateway Enterprise Edition 8.1 prior to 8.1-67.7, 9.0 prior to 9.0-70.5, and 9.1 prior to 9.1-96.4 allows remote malicious users to execute arbitrary code via crafted HTTP header data.

Vulnerable Product Search on Vulmon Subscribe to Product

citrix access gateway 9.1

citrix access gateway 9.0

citrix access gateway 8.1

Exploits

## # $Id: citrix_gateway_actxrb 13670 2011-08-31 00:15:46Z sinn3r $ ## ## # This file is part of the Metasploit Framework and may be subject to # redistribution and commercial restrictions Please see the Metasploit # Framework web site for more information on licensing and terms of use # metasploitcom/framework/ ## require 'msf/core' ...
This Metasploit module exploits a stack based buffer overflow in the Citrix Gateway ActiveX control Exploitation of this vulnerability requires user interaction The victim must click a button in a dialog to begin a scan This is typical interaction that users should be accustom to Exploitation results in code execution with the privileges of the ...