CVE-2009-3760: Code Injection
Static code injection vulnerability in config/writeconfig.php in the sample code in the XenServer Resource Kit in Citrix XenCenterWeb allows remote attackers to inject arbitrary PHP code into include/config.ini.php via the pool1 parameter. NOTE: some of these details are obtained from third party information.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2009-3760?
CVE-2009-3760 is considered a high severity vulnerability due to its potential for remote code execution through static code injection.
How do I fix CVE-2009-3760?
To fix CVE-2009-3760, update to the latest version of Citrix XenCenterWeb that addresses this vulnerability.
What systems are affected by CVE-2009-3760?
CVE-2009-3760 affects the Citrix XenCenterWeb application within the XenServer Resource Kit.
What types of attacks can be executed due to CVE-2009-3760?
Due to CVE-2009-3760, attackers can execute arbitrary PHP code on the affected server, leading to a full compromise.
Is CVE-2009-3760 exploitable remotely?
Yes, CVE-2009-3760 is exploitable remotely, allowing attackers to inject malicious code without local access.