CVE Vulnerabilities

CVE-2010-4566

Published: Jan 14, 2011 | Modified: Sep 22, 2011
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
9.3 HIGH
AV:N/AC:M/Au:N/C:C/I:C/A:C
RedHat/V2
RedHat/V3
Ubuntu

The web authentication form in the NT4 authentication component in Citrix Access Gateway Enterprise Edition 9.2-49.8 and earlier, and the NTLM authentication component in Access Gateway Standard and Advanced Editions before Access Gateway 5.0, allows attackers to execute arbitrary commands via shell metacharacters in the password field.

Affected Software

Name Vendor Start Version End Version
Access_gateway Citrix * 9.2-49.8 (including)
Access_gateway Citrix .8.0-m50.3 (including) .8.0-m50.3 (including)
Access_gateway Citrix 8.0-m48.7 (including) 8.0-m48.7 (including)
Access_gateway Citrix 8.0-m49.2 (including) 8.0-m49.2 (including)
Access_gateway Citrix 8.0-m59.1 (including) 8.0-m59.1 (including)
Access_gateway Citrix 8.1-69.4 (including) 8.1-69.4 (including)
Access_gateway Citrix 9.0.71.3 (including) 9.0.71.3 (including)
Access_gateway Citrix 9.1-104.5 (including) 9.1-104.5 (including)

References