Vulnerability CVE-2007-6267


Published: 2007-12-07   Modified: 2012-02-12

Description:
Citrix EdgeSight 4.2 and 4.5 for Presentation Server, EdgeSight 4.2 and 4.5 for Endpoints, and EdgeSight for NetScaler 1.0 and 1.1 do not properly store database credentials in configuration files, which allows local users to obtain sensitive information.

CVSS2 => (AV:L/AC:L/Au:N/C:P/I:N/A:N)

CVSS Base Score
Impact Subscore
Exploitability Subscore
2.1/10
2.9/10
3.9/10
Exploit range
Attack complexity
Authentication
Local
Low
No required
Confidentiality impact
Integrity impact
Availability impact
Partial
None
None
Affected software
Citrix -> Edgesight for endpoints 
Citrix -> Edgesight for netscaler 
Citrix -> Edgesight for presentation server 

 References:
http://support.citrix.com/article/CTX115281
http://www.securityfocus.com/bid/26705
http://www.securitytracker.com/id?1019050
http://www.vupen.com/english/advisories/2007/4091
https://exchange.xforce.ibmcloud.com/vulnerabilities/38861

Copyright 2022, cxsecurity.com

 

Back to Top