Vulnerabilities > CVE-2015-2682 - Code vulnerability in Citrix Command Center 5.1/5.2

047910
CVSS 5.0 - MEDIUM
Attack vector
NETWORK
Attack complexity
LOW
Privileges required
NONE
Confidentiality impact
PARTIAL
Integrity impact
NONE
Availability impact
NONE
network
low complexity
citrix
CWE-17
exploit available

Summary

Citrix Command Center before 5.1 Build 35.4 and 5.2 before Build 42.7 allows remote attackers to obtain credentials via a direct request to conf/securitydbData.xml.

Vulnerable Configurations

Part Description Count
Application
Citrix
2

Common Weakness Enumeration (CWE)

Exploit-Db

descriptionCitrix Command Center - Credential Disclosure. CVE-2015-2682. Webapps exploit for xml platform
fileexploits/xml/webapps/36441.txt
idEDB-ID:36441
last seen2016-02-04
modified2015-03-19
platformxml
port8443
published2015-03-19
reporterHan Sahin
sourcehttps://www.exploit-db.com/download/36441/
titleCitrix Command Center - Credential Disclosure
typewebapps