6.8
CVSSv2

CVE-2015-2838

Published: 03/04/2015 Updated: 09/10/2018
CVSS v2 Base Score: 6.8 | Impact Score: 6.4 | Exploitability Score: 8.6
VMScore: 685
Vector: AV:N/AC:M/Au:N/C:P/I:P/A:P

Vulnerability Summary

Cross-site request forgery (CSRF) vulnerability in Nitro API in Citrix NetScaler prior to 10.5 build 52.3nc allows remote malicious users to hijack the authentication of administrators for requests that execute arbitrary commands as nsroot via shell metacharacters in the file_name JSON member in params/xen_hotfix/0 to nitro/v1/config/xen_hotfix.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

citrix netscaler 10.5

Exploits

Abstract Securify discovered a command injection vulnerability in xen_hotfix page of the NITRO SDK The attacker-supplied command is executed with elevated privileges (nsroot) This issue can be used to compromise of the entire Citrix SDX appliance and all underling application's and data Tested version This issue was discovered in Citrix Net ...