Citrix Presentation And Desktop Servers Information Disclosure Vulnerability
BID:28047
Info
Citrix Presentation And Desktop Servers Information Disclosure Vulnerability
| Bugtraq ID: | 28047 |
| Class: | Design Error |
| CVE: |
CVE-2008-5107 |
| Remote: | No |
| Local: | Yes |
| Published: | Feb 27 2008 12:00AM |
| Updated: | May 07 2015 05:32PM |
| Credit: | The vendor disclosed this issue. |
| Vulnerable: |
Citrix Presentation Server 4.5 Citrix Desktop Server 1.0 |
| Not Vulnerable: | |
Discussion
Citrix Presentation And Desktop Servers Information Disclosure Vulnerability
Citrix Presentation and Desktop Servers are prone to an information-disclosure vulnerability.
Attackers can exploit this issue to obtain database credentials that will allow them to gain unauthorized access to the database and to obtain potentially sensitive information.
The issue affects Citrix Presentation Server 4.5 and Citrix Desktop Server 1.0.
Citrix Presentation and Desktop Servers are prone to an information-disclosure vulnerability.
Attackers can exploit this issue to obtain database credentials that will allow them to gain unauthorized access to the database and to obtain potentially sensitive information.
The issue affects Citrix Presentation Server 4.5 and Citrix Desktop Server 1.0.
Exploit / POC
Citrix Presentation And Desktop Servers Information Disclosure Vulnerability
An attacker can exploit this issue by using standard tools to view logfiles.
An attacker can exploit this issue by using standard tools to view logfiles.
Solution / Fix
Citrix Presentation And Desktop Servers Information Disclosure Vulnerability
Solution:
The vendor has released an advisory and a fix to address this issue. Please see the references and contact the vendor for more information on resolving the issue.
Solution:
The vendor has released an advisory and a fix to address this issue. Please see the references and contact the vendor for more information on resolving the issue.
References
Citrix Presentation And Desktop Servers Information Disclosure Vulnerability
References:
References: