CVE-2009-3759
citrix xencenterweb - Cross-Site Scripting / SQL Injection / Remote Code Execution
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
4Exploited in Wild
-Decision
Descriptions
Multiple cross-site request forgery (CSRF) vulnerabilities in sample code in the XenServer Resource Kit in Citrix XenCenterWeb allow remote attackers to hijack the authentication of administrators for (1) requests that change the password via the username parameter to config/changepw.php or (2) stop a virtual machine via the stop_vmname parameter to hardstopvm.php. NOTE: some of these details are obtained from third party information.
Múltiples vulnerabilidades de falsificación de petición en sitios cruzados (CSRF) en sample code en el XenServer Resource Kit en Citrix XenCenterWeb en Citrix XenCenterWeb, permite a atacantes remotos secuestras la autenticación de los administradores para (1) peticiones que modifican la contraseña mediante el parámetro "username" en config/changepw.php o (2)parar una máquina virtual mediante el parámetro stop_vmname en hardstopvm.php. NOTA: algunos detalles han sido obtenidos a partir de información de terceros.
CVSS Scores
SSVC
- Decision:-
Timeline
- 2009-07-10 First Exploit
- 2009-10-22 CVE Reserved
- 2009-10-22 CVE Published
- 2024-03-10 EPSS Updated
- 2024-08-07 CVE Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
CWE
- CWE-352: Cross-Site Request Forgery (CSRF)
CAPEC
References (8)
URL | Tag | Source |
---|---|---|
http://securenetwork.it/ricerca/advisory/download/SN-2009-01.txt | Broken Link | |
http://securitytracker.com/id?1022520 | Broken Link | |
https://exchange.xforce.ibmcloud.com/vulnerabilities/51576 | Third Party Advisory |
URL | Date | SRC |
---|---|---|
https://www.exploit-db.com/exploits/9106 | 2009-07-10 | |
http://www.exploit-db.com/exploits/9106 | 2024-08-07 | |
http://www.securityfocus.com/archive/1/504764 | 2024-08-07 | |
http://www.securityfocus.com/bid/35592 | 2024-08-07 |
URL | Date | SRC |
---|
URL | Date | SRC |
---|---|---|
http://www.vupen.com/english/advisories/2009/1814 | 2024-02-08 |
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Citrix Search vendor "Citrix" | Xencenterweb Search vendor "Citrix" for product "Xencenterweb" | - | - |
Affected
|