CVE-2013-6943
https://notcve.org/view.php?id=CVE-2013-6943
Citrix NetScaler Application Delivery Controller (ADC) 9.3.x before 9.3-64.4, 10.0 before 10.0-77.5, and 10.1 before 10.1-118.7 allows remote attackers to conduct an LDAP injection attack via vectors related to SSH and Web management usernames. Citrix NetScaler Application Delivery Controller (ADC) 9.3.x anterior a 9.3-64.4, 10.0 anterior a 10.0-77.5 y 10.1 anterior a 10.1-118.7 permite a atacantes remotos realizar un ataque de inyección LDAP a través de vectores relacionados con SSH y nombres de usuarios de gestión Web. • http://support.citrix.com/article/CTX139049 • CWE-94: Improper Control of Generation of Code ('Code Injection') •
CVE-2013-6944
https://notcve.org/view.php?id=CVE-2013-6944
Cross-site scripting (XSS) vulnerability in the user interface in the AAA TM vServer in Citrix NetScaler Application Delivery Controller (ADC) 9.3.x before 9.3-64.4, 10.0 before 10.0-77.5, and 10.1 before 10.1-118.7 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors. Vulnerabilidad de XSS en la interfaz del usuario en el AAA TM vServer en Citrix NetScaler Application Delivery Controller (ADC) 9.3.x anterior a 9.3-64.4, 10.0 anterior a 10.0-77.5 y 10.1 anterior a 10.1-118.7 permite a atacantes remotos inyectar script Web o HTML arbitrarios a través de vectores no especificados. • http://support.citrix.com/article/CTX139049 • CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') •
CVE-2013-6011
https://notcve.org/view.php?id=CVE-2013-6011
Citrix NetScaler Application Delivery Controller (ADC) 10.0 before 10.0-76.7 allows remote attackers to cause a denial of service (nsconfigd crash and appliance reboot) via a crafted request. Citrix NetScaler Application Delivery Controller (ADC) 10.0 anterior a la versión 10.0-76.7 permite a atacantes remotos provocar una denegación de servicio (cuelgue de nsconfigd y reinicio del dispositivo) a través de una petición diseñada. • http://archives.neohapsis.com/archives/bugtraq/2013-10/0016.html http://support.citrix.com/article/ctx139017 • CWE-20: Improper Input Validation •
CVE-2013-2767
https://notcve.org/view.php?id=CVE-2013-2767
Unspecified vulnerability in Citrix NetScaler Access Gateway Enterprise Edition (AGEE) before 9.3.62.4 and 10.x through 10.0.74.4, and NetScaler AGEE Common Criteria build before 9.3.53.6, allows remote attackers to bypass intended intranet access restrictions via unknown vectors. Vulnerabilidad no especificada en Citrix NetScaler Access Gateway Enterprise Edition (AGEE) antes de v9.3.62.4 y v10.x hasta v10.0.74.4 y NetScaler AGEE Common Criteria antes de v9.3.53.6, permite a atacantes remotos evitar las restricciones de acceso a la intranet destinados a través de vectores desconocidos. • http://support.citrix.com/article/ctx137238 http://www.kb.cert.org/vuls/id/521612 •
CVE-2009-2213
https://notcve.org/view.php?id=CVE-2009-2213
The default configuration of the Security global settings on the Citrix NetScaler Access Gateway appliance with Enterprise Edition firmware 9.0, 8.1, and earlier specifies Allow for the Default Authorization Action option, which might allow remote authenticated users to bypass intended access restrictions. La configuración por defecto en las características de seguridad globales en el appliance Citrix NetScaler Access Gateway con el firmware Enterprise Edition 9.0, 8.1 y versiones anteriores especifica la opción "Allow for the Default Authorization Action" lo que puede permitir a usuarios remotos autenticados evitar las restricciones de acceso previstas. • http://support.citrix.com/article/CTX118770 http://www.securityfocus.com/bid/35422 http://www.vupen.com/english/advisories/2009/1641 https://exchange.xforce.ibmcloud.com/vulnerabilities/51274 • CWE-863: Incorrect Authorization •