citrix xencenterweb CVE-2009-3759 is a vulnerability in Citrix Xencenterweb
Published on October 22, 2009

Multiple cross-site request forgery (CSRF) vulnerabilities in sample code in the XenServer Resource Kit in Citrix XenCenterWeb allow remote attackers to hijack the authentication of administrators for (1) requests that change the password via the username parameter to config/changepw.php or (2) stop a virtual machine via the stop_vmname parameter to hardstopvm.php. NOTE: some of these details are obtained from third party information.

NVD


Products Associated with CVE-2009-3759

Want to know whenever a new CVE is published for Citrix Xencenterweb? stack.watch will email you.

 

Exploit Probability

EPSS
1.71%
Percentile
82.24%

EPSS (Exploit Prediction Scoring System) scores estimate the probability that a vulnerability will be exploited in the wild within the next 30 days. The percentile shows you how this score compares to all other vulnerabilities.