CVE-2007-6267
Summary
| CVE | CVE-2007-6267 |
|---|---|
| State | PUBLISHED |
| Assigner | mitre |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2007-12-07 11:46:00 UTC |
| Updated | 2026-04-23 00:35:47 UTC |
| Description | Citrix EdgeSight 4.2 and 4.5 for Presentation Server, EdgeSight 4.2 and 4.5 for Endpoints, and EdgeSight for NetScaler 1.0 and 1.1 do not properly store database credentials in configuration files, which allows local users to obtain sensitive information. |
Risk And Classification
CVSS v2.0 Breakdown
Access Vector
LocalAccess Complexity
LowAuthentication
NoneConfidentiality
PartialIntegrity
NoneAvailability
NoneAV:L/AC:L/Au:N/C:P/I:N/A:N
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Citrix | Edgesight For Endpoints | 4.2 | All | All | All |
| Application | Citrix | Edgesight For Endpoints | 4.5 | All | All | All |
| Application | Citrix | Edgesight For Netscaler | 1.0 | All | All | All |
| Application | Citrix | Edgesight For Netscaler | 1.1 | All | All | All |
| Application | Citrix | Edgesight For Presentation Server | 4.2 | All | All | All |
| Application | Citrix | Edgesight For Presentation Server | 4.5 | All | All | All |
Vendor Declared Affected Products
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| Webmail : Solution de messagerie professionnelle - OVHcloud- OVH | af854a3a-2127-422b-91ae-364da2661108 | www.vupen.com | |
| Citrix EdgeSight for Endpoints and Presentation Server Database Credential Disclosure Weakness | af854a3a-2127-422b-91ae-364da2661108 | www.securityfocus.com | Exploit, Patch |
| Citrix EdgeSight Configuration File Information Disclosure Weakness - Advisories - Secunia | af854a3a-2127-422b-91ae-364da2661108 | secunia.com | Vendor Advisory |
| IBM X-Force Exchange | af854a3a-2127-422b-91ae-364da2661108 | exchange.xforce.ibmcloud.com | |
| Citrix EdgeSight May Disclose Database Password to Local Users - SecurityTracker | af854a3a-2127-422b-91ae-364da2661108 | www.securitytracker.com | |
| Weakness in Citrix EdgeSight for Endpoints and Citrix EdgeSight for Presentation Server could result in information disclosure | af854a3a-2127-422b-91ae-364da2661108 | support.citrix.com | Patch |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.