Static Code Injection Vulnerability in XenCenterWeb by Citrix
CVE-2009-3760
Currently unrated
Summary
A static code injection vulnerability exists in the config/writeconfig.php file within the XenServer Resource Kit, affecting Citrix XenCenterWeb. This vulnerability allows remote attackers to inject arbitrary PHP code into the include/config.ini.php file by manipulating the pool1 parameter. If exploited, it could potentially compromise the integrity of the affected system, allowing unauthorized access and control.
References
EPSS Score
6% chance of being exploited in the next 30 days.
Timeline
Vulnerability published
Vulnerability Reserved