{"api_version":"1","generated_at":"2026-07-23T07:49:13+00:00","cve":"CVE-2007-6267","urls":{"html":"https://cve.report/CVE-2007-6267","api":"https://cve.report/api/cve/CVE-2007-6267.json","docs":"https://cve.report/api","cve_org":"https://www.cve.org/CVERecord?id=CVE-2007-6267","nvd":"https://nvd.nist.gov/vuln/detail/CVE-2007-6267"},"summary":{"title":"CVE-2007-6267","description":"Citrix EdgeSight 4.2 and 4.5 for Presentation Server, EdgeSight 4.2 and 4.5 for Endpoints, and EdgeSight for NetScaler 1.0 and 1.1 do not properly store database credentials in configuration files, which allows local users to obtain sensitive information.","state":"PUBLISHED","assigner":"mitre","published_at":"2007-12-07 11:46:00","updated_at":"2026-04-23 00:35:47"},"problem_types":["CWE-255","n/a"],"metrics":[{"version":"2.0","source":"nvd@nist.gov","type":"Primary","score":"2.1","severity":"","vector":"AV:L/AC:L/Au:N/C:P/I:N/A:N","data":{"version":"2.0","vectorString":"AV:L/AC:L/Au:N/C:P/I:N/A:N","baseScore":2.1,"accessVector":"LOCAL","accessComplexity":"LOW","authentication":"NONE","confidentialityImpact":"PARTIAL","integrityImpact":"NONE","availabilityImpact":"NONE"}}],"references":[{"url":"http://www.vupen.com/english/advisories/2007/4091","name":"http://www.vupen.com/english/advisories/2007/4091","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"Webmail : Solution de messagerie professionnelle - OVHcloud- OVH","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://www.securityfocus.com/bid/26705","name":"http://www.securityfocus.com/bid/26705","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Exploit","Patch"],"title":"Citrix EdgeSight for Endpoints and Presentation Server Database Credential Disclosure Weakness","mime":"text/html","httpstatus":"200","archivestatus":"0"},{"url":"http://secunia.com/advisories/27935","name":"http://secunia.com/advisories/27935","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Vendor Advisory"],"title":"Citrix EdgeSight Configuration File Information Disclosure Weakness - Advisories - Secunia","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/38861","name":"https://exchange.xforce.ibmcloud.com/vulnerabilities/38861","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"IBM X-Force Exchange","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://www.securitytracker.com/id?1019050","name":"http://www.securitytracker.com/id?1019050","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"Citrix EdgeSight May Disclose Database Password to Local Users - SecurityTracker","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://support.citrix.com/article/CTX115281","name":"http://support.citrix.com/article/CTX115281","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Patch"],"title":"Weakness in Citrix EdgeSight for Endpoints and Citrix EdgeSight for Presentation Server could result in information disclosure","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://www.cve.org/CVERecord?id=CVE-2007-6267","name":"CVE Program record","refsource":"CVE.ORG","tags":["canonical"]},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2007-6267","name":"NVD vulnerability detail","refsource":"NVD","tags":["canonical","analysis"]}],"affected":[{"source":"CNA","vendor":"n/a","product":"n/a","version":"affected n/a","platforms":[]}],"timeline":[],"solutions":[],"workarounds":[],"exploits":[],"credits":[],"nvd_cpes":[{"cve_year":"2007","cve_id":"6267","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"citrix","cpe5":"edgesight_for_endpoints","cpe6":"4.2","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2007","cve_id":"6267","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"citrix","cpe5":"edgesight_for_endpoints","cpe6":"4.5","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2007","cve_id":"6267","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"citrix","cpe5":"edgesight_for_netscaler","cpe6":"1.0","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2007","cve_id":"6267","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"citrix","cpe5":"edgesight_for_netscaler","cpe6":"1.1","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2007","cve_id":"6267","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"citrix","cpe5":"edgesight_for_presentation_server","cpe6":"4.2","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2007","cve_id":"6267","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"citrix","cpe5":"edgesight_for_presentation_server","cpe6":"4.5","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"}],"vendor_comments":[],"enrichments":{"kev":null,"epss":null,"legacy_qids":[]},"source_records":{"cve_program":{"containers":{"adp":[{"providerMetadata":{"dateUpdated":"2024-08-07T16:02:35.701Z","orgId":"af854a3a-2127-422b-91ae-364da2661108","shortName":"CVE"},"references":[{"tags":["x_refsource_CONFIRM","x_transferred"],"url":"http://support.citrix.com/article/CTX115281"},{"name":"edgesight-configuration-file-info-disclosure(38861)","tags":["vdb-entry","x_refsource_XF","x_transferred"],"url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/38861"},{"name":"ADV-2007-4091","tags":["vdb-entry","x_refsource_VUPEN","x_transferred"],"url":"http://www.vupen.com/english/advisories/2007/4091"},{"name":"1019050","tags":["vdb-entry","x_refsource_SECTRACK","x_transferred"],"url":"http://www.securitytracker.com/id?1019050"},{"name":"26705","tags":["vdb-entry","x_refsource_BID","x_transferred"],"url":"http://www.securityfocus.com/bid/26705"},{"name":"27935","tags":["third-party-advisory","x_refsource_SECUNIA","x_transferred"],"url":"http://secunia.com/advisories/27935"}],"title":"CVE Program Container"}],"cna":{"affected":[{"product":"n/a","vendor":"n/a","versions":[{"status":"affected","version":"n/a"}]}],"datePublic":"2007-12-05T00:00:00.000Z","descriptions":[{"lang":"en","value":"Citrix EdgeSight 4.2 and 4.5 for Presentation Server, EdgeSight 4.2 and 4.5 for Endpoints, and EdgeSight for NetScaler 1.0 and 1.1 do not properly store database credentials in configuration files, which allows local users to obtain sensitive information."}],"problemTypes":[{"descriptions":[{"description":"n/a","lang":"en","type":"text"}]}],"providerMetadata":{"dateUpdated":"2017-08-07T12:57:01.000Z","orgId":"8254265b-2729-46b6-b9e3-3dfca2d5bfca","shortName":"mitre"},"references":[{"tags":["x_refsource_CONFIRM"],"url":"http://support.citrix.com/article/CTX115281"},{"name":"edgesight-configuration-file-info-disclosure(38861)","tags":["vdb-entry","x_refsource_XF"],"url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/38861"},{"name":"ADV-2007-4091","tags":["vdb-entry","x_refsource_VUPEN"],"url":"http://www.vupen.com/english/advisories/2007/4091"},{"name":"1019050","tags":["vdb-entry","x_refsource_SECTRACK"],"url":"http://www.securitytracker.com/id?1019050"},{"name":"26705","tags":["vdb-entry","x_refsource_BID"],"url":"http://www.securityfocus.com/bid/26705"},{"name":"27935","tags":["third-party-advisory","x_refsource_SECUNIA"],"url":"http://secunia.com/advisories/27935"}],"x_legacyV4Record":{"CVE_data_meta":{"ASSIGNER":"cve@mitre.org","ID":"CVE-2007-6267","STATE":"PUBLIC"},"affects":{"vendor":{"vendor_data":[{"product":{"product_data":[{"product_name":"n/a","version":{"version_data":[{"version_value":"n/a"}]}}]},"vendor_name":"n/a"}]}},"data_format":"MITRE","data_type":"CVE","data_version":"4.0","description":{"description_data":[{"lang":"eng","value":"Citrix EdgeSight 4.2 and 4.5 for Presentation Server, EdgeSight 4.2 and 4.5 for Endpoints, and EdgeSight for NetScaler 1.0 and 1.1 do not properly store database credentials in configuration files, which allows local users to obtain sensitive information."}]},"problemtype":{"problemtype_data":[{"description":[{"lang":"eng","value":"n/a"}]}]},"references":{"reference_data":[{"name":"http://support.citrix.com/article/CTX115281","refsource":"CONFIRM","url":"http://support.citrix.com/article/CTX115281"},{"name":"edgesight-configuration-file-info-disclosure(38861)","refsource":"XF","url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/38861"},{"name":"ADV-2007-4091","refsource":"VUPEN","url":"http://www.vupen.com/english/advisories/2007/4091"},{"name":"1019050","refsource":"SECTRACK","url":"http://www.securitytracker.com/id?1019050"},{"name":"26705","refsource":"BID","url":"http://www.securityfocus.com/bid/26705"},{"name":"27935","refsource":"SECUNIA","url":"http://secunia.com/advisories/27935"}]}}}},"cveMetadata":{"assignerOrgId":"8254265b-2729-46b6-b9e3-3dfca2d5bfca","assignerShortName":"mitre","cveId":"CVE-2007-6267","datePublished":"2007-12-07T11:00:00.000Z","dateReserved":"2007-12-07T00:00:00.000Z","dateUpdated":"2024-08-07T16:02:35.701Z","state":"PUBLISHED"},"dataType":"CVE_RECORD","dataVersion":"5.1"},"nvd":{"publishedDate":"2007-12-07 11:46:00","lastModifiedDate":"2026-04-23 00:35:47","problem_types":["CWE-255","n/a"],"metrics":{"cvssMetricV2":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"2.0","vectorString":"AV:L/AC:L/Au:N/C:P/I:N/A:N","baseScore":2.1,"accessVector":"LOCAL","accessComplexity":"LOW","authentication":"NONE","confidentialityImpact":"PARTIAL","integrityImpact":"NONE","availabilityImpact":"NONE"},"baseSeverity":"LOW","exploitabilityScore":3.9,"impactScore":2.9,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":false}]},"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:citrix:edgesight_for_endpoints:4.2:*:*:*:*:*:*:*","matchCriteriaId":"A51F3443-CC16-40A2-8A43-5E2A6DA1C68B"},{"vulnerable":true,"criteria":"cpe:2.3:a:citrix:edgesight_for_endpoints:4.5:*:*:*:*:*:*:*","matchCriteriaId":"3807F821-1E3B-4E52-8E14-A6F22DA28D06"},{"vulnerable":true,"criteria":"cpe:2.3:a:citrix:edgesight_for_netscaler:1.0:*:*:*:*:*:*:*","matchCriteriaId":"03B79B3B-A526-496F-84F1-9855C1F1A67D"},{"vulnerable":true,"criteria":"cpe:2.3:a:citrix:edgesight_for_netscaler:1.1:*:*:*:*:*:*:*","matchCriteriaId":"B62588DC-6A3B-4A5D-A822-15268C209696"},{"vulnerable":true,"criteria":"cpe:2.3:a:citrix:edgesight_for_presentation_server:4.2:*:*:*:*:*:*:*","matchCriteriaId":"079DDF6A-305E-4775-B07D-24F222782160"},{"vulnerable":true,"criteria":"cpe:2.3:a:citrix:edgesight_for_presentation_server:4.5:*:*:*:*:*:*:*","matchCriteriaId":"3FF901DE-4F7B-49A1-A4B9-31FEDF559BFA"}]}]}]},"legacy_mitre":{"record":{"CveYear":"2007","CveId":"6267","Ordinal":"1","Title":"CVE-2007-6267","CVE":"CVE-2007-6267","Year":"2007"},"notes":[{"CveYear":"2007","CveId":"6267","Ordinal":"1","NoteData":"Citrix EdgeSight 4.2 and 4.5 for Presentation Server, EdgeSight 4.2 and 4.5 for Endpoints, and EdgeSight for NetScaler 1.0 and 1.1 do not properly store database credentials in configuration files, which allows local users to obtain sensitive information.","Type":"Description","Title":"CVE-2007-6267"},{"CveYear":"2007","CveId":"6267","Ordinal":"2","NoteData":"2007-12-07","Type":"Other","Title":"Published"},{"CveYear":"2007","CveId":"6267","Ordinal":"3","NoteData":"2017-08-07","Type":"Other","Title":"Modified"}]}}}