First published: Thu Sep 17 2015(Updated: )
Cross-site scripting (XSS) vulnerability in the Administrative Web Interface in Citrix NetScaler Application Delivery Controller (ADC) and NetScaler Gateway before 10.1 Build 132.8, 10.5 before Build 57.7, and 10.5e before Build 56.1505.e allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Citrix Application Delivery Controller Firmware | =10.1 | |
Citrix Application Delivery Controller Firmware | =10.5 | |
Citrix Application Delivery Controller Firmware | =10.5e | |
Citrix Netscaler Gateway Firmware | =10.1 | |
Citrix Netscaler Gateway Firmware | =10.5 | |
Citrix Netscaler Gateway Firmware | =10.5e |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2015-6672 is classified as a medium severity vulnerability due to its potential for cross-site scripting attacks.
To fix CVE-2015-6672, upgrade to Citrix NetScaler Application Delivery Controller or Gateway versions 10.1 Build 132.8, 10.5 Build 57.7, or 10.5e Build 56.1505.e or later.
CVE-2015-6672 affects Citrix NetScaler Application Delivery Controller Firmware and NetScaler Gateway Firmware versions below the specified builds.
CVE-2015-6672 allows remote attackers to inject arbitrary web scripts or HTML into the Administrative Web Interface.
Yes, CVE-2015-6672 can be exploited remotely due to vulnerabilities in the web interface.