
CVE-2021-28113 – Okta Access Gateway 2020.5.5 Authenticated Remote Root
https://notcve.org/view.php?id=CVE-2021-28113
02 Apr 2021 — A command injection vulnerability in the cookieDomain and relayDomain parameters of Okta Access Gateway before 2020.9.3 allows attackers (with admin access to the Okta Access Gateway UI) to execute OS commands as a privileged system account. Una vulnerabilidad de inyección de comandos en los parámetros cookieDomain y relayDomain de Okta Access Gateway versiones anteriores a 2020.9.3, permite a atacantes (con acceso de administrador a la interfaz de usuario de Okta Access Gateway) ejecutar comandos del siste... • https://packetstorm.news/files/id/163428 • CWE-78: Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') •

CVE-2010-4566 – Citrix Access Gateway - Command Execution
https://notcve.org/view.php?id=CVE-2010-4566
14 Jan 2011 — The web authentication form in the NT4 authentication component in Citrix Access Gateway Enterprise Edition 9.2-49.8 and earlier, and the NTLM authentication component in Access Gateway Standard and Advanced Editions before Access Gateway 5.0, allows attackers to execute arbitrary commands via shell metacharacters in the password field. Vulnerabilidad no especificada en el componente de autenticación NT4 en Citrix Access Gateway Enterprise Edition v9.2-49.8 y anteriores, y el componente de autenticación NTL... • https://www.exploit-db.com/exploits/16916 •

CVE-2009-2213
https://notcve.org/view.php?id=CVE-2009-2213
25 Jun 2009 — The default configuration of the Security global settings on the Citrix NetScaler Access Gateway appliance with Enterprise Edition firmware 9.0, 8.1, and earlier specifies Allow for the Default Authorization Action option, which might allow remote authenticated users to bypass intended access restrictions. La configuración por defecto en las características de seguridad globales en el appliance Citrix NetScaler Access Gateway con el firmware Enterprise Edition 9.0, 8.1 y versiones anteriores especifica la o... • http://support.citrix.com/article/CTX118770 • CWE-863: Incorrect Authorization •