Vulnerabilities > CVE-2010-4566 - Unspecified vulnerability in Citrix Access Gateway

047910
CVSS 9.3 - CRITICAL
Attack vector
NETWORK
Attack complexity
MEDIUM
Privileges required
NONE
Confidentiality impact
COMPLETE
Integrity impact
COMPLETE
Availability impact
COMPLETE
network
citrix
critical
exploit available
metasploit

Summary

The web authentication form in the NT4 authentication component in Citrix Access Gateway Enterprise Edition 9.2-49.8 and earlier, and the NTLM authentication component in Access Gateway Standard and Advanced Editions before Access Gateway 5.0, allows attackers to execute arbitrary commands via shell metacharacters in the password field.

Exploit-Db

  • descriptionCitrix Access Gateway - Command Injection Vulnerability. CVE-2010-4566. Remote exploit for linux platform
    idEDB-ID:15806
    last seen2016-02-01
    modified2010-12-22
    published2010-12-22
    reporterGeorge D. Gal
    sourcehttps://www.exploit-db.com/download/15806/
    titleCitrix Access Gateway - Command Injection Vulnerability
  • descriptionCitrix Access Gateway Command Execution. CVE-2010-4566. Remote exploit for linux platform
    fileexploits/linux/remote/16916.rb
    idEDB-ID:16916
    last seen2016-02-02
    modified2011-03-03
    platformlinux
    port
    published2011-03-03
    reportermetasploit
    sourcehttps://www.exploit-db.com/download/16916/
    titleCitrix Access Gateway - Command Execution
    typeremote

Metasploit

descriptionThe Citrix Access Gateway provides support for multiple authentication types. When utilizing the external legacy NTLM authentication module known as ntlm_authenticator the Access Gateway spawns the Samba 'samedit' command line utility to verify a user's identity and password. By embedding shell metacharacters in the web authentication form it is possible to execute arbitrary commands on the Access Gateway.
idMSF:EXPLOIT/UNIX/WEBAPP/CITRIX_ACCESS_GATEWAY_EXEC
last seen2020-06-14
modified2017-07-24
published2011-03-03
references
reporterRapid7
sourcehttps://github.com/rapid7/metasploit-framework/blob/master//modules/exploits/unix/webapp/citrix_access_gateway_exec.rb
titleCitrix Access Gateway Command Execution

Packetstorm

Seebug

bulletinFamilyexploit
descriptionNo description provided by source.
idSSV:20307
last seen2017-11-19
modified2010-12-22
published2010-12-22
reporterRoot
sourcehttps://www.seebug.org/vuldb/ssvid-20307
titleCitrix Access Gateway Command Injection Vulnerability