// For flags

CVE-2007-0011

 

Severity Score

5.0
*CVSS v2

Exploit Likelihood

*EPSS

Affected Versions

*CPE

Public Exploits

0
*Multiple Sources

Exploited in Wild

-
*KEV

Decision

-
*SSVC
Descriptions

The web portal interface in Citrix Access Gateway (aka Citrix Advanced Access Control) before Advanced Edition 4.5 HF1 places a session ID in the URL, which allows context-dependent attackers to hijack sessions by reading "residual information", including the a referer log, browser history, or browser cache.

El interfaz del portal web de Citrix Access Gateway (también conocido como Citrix Advanced Access Control) versiones anteriores a Advanced Edition 4.5 HF1, sitúa un ID de sesión en el URL, lo cual permite a atacantes locales o remotos dependientes del contexto secuestrar sesiones al leer "información residual", incluyendo un fichero de trazas utilizado, historial del navegador, o la caché del navegador.

*Credits: N/A
CVSS Scores
Attack Vector
Network
Attack Complexity
Low
Authentication
None
Confidentiality
Partial
Integrity
None
Availability
None
* Common Vulnerability Scoring System
SSVC
  • Decision:-
Exploitation
-
Automatable
-
Tech. Impact
-
* Organization's Worst-case Scenario
Timeline
  • 2007-01-01 CVE Reserved
  • 2007-10-23 CVE Published
  • 2024-08-07 CVE Updated
  • 2024-10-16 EPSS Updated
  • ---------- Exploited in Wild
  • ---------- KEV Due Date
  • ---------- First Exploit
CWE
  • CWE-200: Exposure of Sensitive Information to an Unauthorized Actor
CAPEC
Affected Vendors, Products, and Versions
Vendor Product Version Other Status
Vendor Product Version Other Status <-- --> Vendor Product Version Other Status
Citrix
Search vendor "Citrix"
Access Gateway
Search vendor "Citrix" for product "Access Gateway"
4.0
Search vendor "Citrix" for product "Access Gateway" and version "4.0"
-
Affected
Citrix
Search vendor "Citrix"
Access Gateway
Search vendor "Citrix" for product "Access Gateway"
4.2
Search vendor "Citrix" for product "Access Gateway" and version "4.2"
-
Affected
Citrix
Search vendor "Citrix"
Access Gateway
Search vendor "Citrix" for product "Access Gateway"
4.5
Search vendor "Citrix" for product "Access Gateway" and version "4.5"
advanced
Affected
Citrix
Search vendor "Citrix"
Access Gateway
Search vendor "Citrix" for product "Access Gateway"
4.5
Search vendor "Citrix" for product "Access Gateway" and version "4.5"
standard
Affected