SQL Injection Vulnerability in Citrix XenCenterWeb
CVE-2009-3758
Currently unrated
Summary
An SQL injection vulnerability exists in the login.php file of the sample code provided within the XenServer Resource Kit for Citrix XenCenterWeb. This flaw allows remote attackers to manipulate the username parameter in the login process to execute arbitrary SQL commands on the database backend. Exploiting this vulnerability could lead to unauthorized access, data leakage, and potential compromise of systems relying on XenCenterWeb.
References
Timeline
Vulnerability published
Vulnerability Reserved