22 results (0.003 seconds)

CVSS: 8.8EPSS: 1%CPEs: 9EXPL: 0

In Citrix XenMobile Server through 10.12 RP9, there is an Authenticated Directory Traversal vulnerability, leading to remote code execution. En Citrix XenMobile Server versiones hasta 10.12 RP9, se presenta una vulnerabilidad de salto de directorio autenticado, conllevando a una ejecución de código remota • https://docs.citrix.com/en-us/xenmobile/server/document-history.html https://gist.github.com/tree-chtsec/30932b9c94b8c7e4209d22b8b52d597f https://support.citrix.com/article/CTX370551 https://www.chtsecurity.com/news/09be10ae-b50e-46c9-8ce7-2e995fd988fe • CWE-22: Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') •

CVSS: 9.0EPSS: 0%CPEs: 11EXPL: 0

Citrix XenMobile Server 10.12 through RP11, 10.13 through RP7, and 10.14 through RP4 allows Command Injection. Citrix XenMobile Server 10.12 hasta RP11, 10.13 hasta RP7 y 10.14 hasta RP4 permiten la inyección de comandos • https://support.citrix.com/article/CTX370551 https://support.citrix.com/search https://www.chtsecurity.com/news/09be10ae-b50e-46c9-8ce7-2e995fd988fe • CWE-77: Improper Neutralization of Special Elements used in a Command ('Command Injection') •

CVSS: 9.0EPSS: 1%CPEs: 9EXPL: 0

In Citrix XenMobile Server through 10.12 RP9, there is an Authenticated Command Injection vulnerability, leading to remote code execution with root privileges. En Citrix XenMobile Server versiones hasta 10.12 RP9, se presenta una vulnerabilidad de Inyección de Comandos Autenticados, conllevando a una ejecución de código remota con privilegios root • https://docs.citrix.com/en-us/xenmobile/server/document-history.html https://gist.github.com/tree-chtsec/766f81e22ae383987d75eedb3b23b709 https://support.citrix.com/article/CTX370551 https://www.chtsecurity.com/news/09be10ae-b50e-46c9-8ce7-2e995fd988fe • CWE-77: Improper Neutralization of Special Elements used in a Command ('Command Injection') •

CVSS: 7.5EPSS: 0%CPEs: 18EXPL: 0

Improper authentication in Citrix XenMobile Server 10.12 before RP2, Citrix XenMobile Server 10.11 before RP4, Citrix XenMobile Server 10.10 before RP6 and Citrix XenMobile Server before 10.9 RP5 leads to the ability to access sensitive files. Una autenticación inapropiada en Citrix XenMobile Server versiones 10.12 anteriores a RP2, Citrix XenMobile Server versiones 10.11 anteriores a RP4, Citrix XenMobile Server versiones 10.10 anteriores a RP6 y Citrix XenMobile Server versiones anteriores a 10.9 RP5, conlleva a la capacidad de acceder a archivos confidenciales • https://support.citrix.com/article/CTX277457 • CWE-287: Improper Authentication •

CVSS: 9.8EPSS: 0%CPEs: 16EXPL: 0

Improper access control in Citrix XenMobile Server 10.12 before RP3, Citrix XenMobile Server 10.11 before RP6, Citrix XenMobile Server 10.10 RP6 and Citrix XenMobile Server before 10.9 RP5 allows access to privileged functionality. Un control de acceso inapropiado en Citrix XenMobile Server versiones 10.12 anteriores a RP3, Citrix XenMobile Server versiones 10.11 anteriores a RP6, Citrix XenMobile Server versión 10.10 RP6 y Citrix XenMobile Server versiones anteriores a 10.9 RP5, permite acceso a funcionalidades privilegiadas. • https://support.citrix.com/article/CTX277457 • CWE-749: Exposed Dangerous Method or Function CWE-863: Incorrect Authorization •