Lucene search

K
cve[email protected]CVE-2009-3758
HistoryOct 22, 2009 - 5:30 p.m.

CVE-2009-3758

2009-10-2217:30:00
CWE-89
web.nvd.nist.gov
21
xenserver
resource kit
sql injection
login.php
citrix
xencenterweb
nvd
cve-2009-3758

7.5 High

CVSS2

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:N/AC:L/Au:N/C:P/I:P/A:P

8.4 High

AI Score

Confidence

Low

0.005 Low

EPSS

Percentile

77.0%

SQL injection vulnerability in login.php in sample code in the XenServer Resource Kit in Citrix XenCenterWeb allows remote attackers to execute arbitrary SQL commands via the username parameter. NOTE: some of these details are obtained from third party information.

Affected configurations

NVD
Node
citrixxencenterweb

7.5 High

CVSS2

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:N/AC:L/Au:N/C:P/I:P/A:P

8.4 High

AI Score

Confidence

Low

0.005 Low

EPSS

Percentile

77.0%

Related for CVE-2009-3758