SQL Injection Vulnerability in Citrix XenCenterWeb
CVE-2009-3758

Currently unrated

Key Information:

Vendor
Citrix
Vendor
CVE Published:
22 October 2009

Summary

An SQL injection vulnerability exists in the login.php file of the sample code provided within the XenServer Resource Kit for Citrix XenCenterWeb. This flaw allows remote attackers to manipulate the username parameter in the login process to execute arbitrary SQL commands on the database backend. Exploiting this vulnerability could lead to unauthorized access, data leakage, and potential compromise of systems relying on XenCenterWeb.

References

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.