PoC Index

CVE-2015-2838

MEDIUM 6.8EPSS 2.9%

Cross-site request forgery (CSRF) vulnerability in Nitro API in Citrix NetScaler before 10.5 build 52.3nc allows remote attackers to hijack the authentication of administrators for requests that execute arbitrary commands as nsroot via shell metacharacters in the file_name JSON member in params/xen_hotfix/0 to nitro/v1/config/xen_hotfix.

CVSS v2.0
6.8 MEDIUMAV:N/AC:M/Au:N/C:P/I:P/A:P
EPSS
2.86% chance of exploitation in the next 30 days, 86th percentile
Published
2015-04-03
Updated
2024-08-06

ExploitDB entries (1)

References

Related