CVE-2014-4346: XSS
Cross-site scripting (XSS) vulnerability in administration user interface in Citrix NetScaler Application Delivery Controller (ADC) and NetScaler Gateway (formerly Access Gateway Enterprise Edition) 10.1 before 10.1-126.12 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2014-4346?
CVE-2014-4346 has a high severity due to its potential for remote code execution via XSS in the Citrix NetScaler administration interface.
How do I fix CVE-2014-4346?
To fix CVE-2014-4346, upgrade to a patched version of Citrix NetScaler Application Delivery Controller or NetScaler Gateway, specifically version 10.1-126.12 or later.
Which products are affected by CVE-2014-4346?
CVE-2014-4346 affects Citrix NetScaler Application Delivery Controller and Citrix NetScaler Gateway versions prior to 10.1-126.12.
What type of vulnerability is CVE-2014-4346?
CVE-2014-4346 is a cross-site scripting (XSS) vulnerability that allows for the injection of arbitrary web scripts or HTML.
Can CVE-2014-4346 be exploited remotely?
Yes, CVE-2014-4346 can be exploited remotely, allowing attackers to execute malicious scripts without physical access to the affected systems.