CVE-2010-4566
43Vexday Risk Score
Patch soon. It has a working public exploit.
ssvc Attendepss 28%
from disclosure to weapon0 days
Published on NVDJan 14
1st PoCDec 22
metasploitDec 21
exploitation probability
28%top 2% of all CVEs
observed exploitation
nono source reports it
3 public exploit(s)
The web authentication form in the NT4 authentication component in Citrix Access Gateway Enterprise Edition 9.2-49.8 and earlier, and the NTLM authentication component in Access Gateway Standard and Advanced Editions before Access Gateway 5.0, allows attackers to execute arbitrary commands via shell metacharacters in the password field.
Affected products
n/a · n/apublic PoCs found — 3
cve_referencewww.exploit-db.com/exploits/16916unverifiedexploitdbwww.exploit-db.com/exploits/16916unverifiedexploitdbwww.exploit-db.com/exploits/15806unverified⚠ Public resources, to assess the exposure of systems you control or are authorized to test. Test only with authorization.