CVE-2002-2426
Summary
| CVE | CVE-2002-2426 |
|---|---|
| State | PUBLISHED |
| Assigner | mitre |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2002-12-31 05:00:00 UTC |
| Updated | 2025-04-03 01:03:51 UTC |
| Description | Cross-site request forgery (CSRF) vulnerability in Citrix Presentation Server 4.0 and 4.5, MetaFrame Presentation Server 3.0, and Access Essentials 1.0 through 2.0 allows remote attackers to execute arbitrary published applications, and possibly other programs, as authenticated users via the InitialProgram key in an ICA connection. NOTE: some of these details are obtained from third party information. |
Risk And Classification
CVSS v2.0 Breakdown
Access Vector
NetworkAccess Complexity
MediumAuthentication
NoneConfidentiality
NoneIntegrity
PartialAvailability
NoneAV:N/AC:M/Au:N/C:N/I:P/A:N
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Citrix | Access Essentials | 1.0 | All | All | All |
| Application | Citrix | Access Essentials | 1.5 | All | All | All |
| Application | Citrix | Access Essentials | 2.0 | All | All | All |
| Application | Citrix | Metaframe Presentation Server | 3.0 | All | All | All |
| Application | Citrix | Presentation Server | 4.0 | All | All | All |
| Application | Citrix | Presentation Server | 4.5 | All | All | All |
Vendor Declared Affected Products
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| Files ≈ Packet Storm | af854a3a-2127-422b-91ae-364da2661108 | packetstormsecurity.org | |
| CITRIX: Owning the Legitimate Backdoor | GNUCITIZEN | af854a3a-2127-422b-91ae-364da2661108 | www.gnucitizen.org | |
| Citrix Presentation Server Published Application Information May Let Remote Users Execute Arbitrary Commands - SecurityTracker | af854a3a-2127-422b-91ae-364da2661108 | www.securitytracker.com | |
| Citrix Presentation Server Remote Unauthorized Code Execution Vulnerability | af854a3a-2127-422b-91ae-364da2661108 | www.securityfocus.com | |
| Webmail : Solution de messagerie professionnelle - OVHcloud- OVH | af854a3a-2127-422b-91ae-364da2661108 | www.vupen.com | |
| Citrix Presentation Server Published Application Execution Weakness - Advisories - Secunia | af854a3a-2127-422b-91ae-364da2661108 | secunia.com | Vendor Advisory |
| CTX115245 - Vulnerability in Citrix Presentation Server could result in unauthorized code execution - Citrix Knowledge Center | af854a3a-2127-422b-91ae-364da2661108 | support.citrix.com | |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.