CVE-2009-3759
Last modified
CVE-2009-3759 is a high-severity vulnerability rated 8.8/10 on the CVSS scale. Multiple cross-site request forgery (CSRF) vulnerabilities in sample code in the XenServer Resource Kit in Citrix XenCenterWeb allow remote attackers to hijack the authentication of administrators for (1) requests that change the password via the username parameter to config/changepw.php or (2) stop a virtual machine via the stop_vmname parameter to hardstopvm.php. NOTE: some of these details are obtained from third party information.. EPSS estimates a 2.29% chance of exploitation in the next 30 days.
Description
Multiple cross-site request forgery (CSRF) vulnerabilities in sample code in the XenServer Resource Kit in Citrix XenCenterWeb allow remote attackers to hijack the authentication of administrators for (1) requests that change the password via the username parameter to config/changepw.php or (2) stop a virtual machine via the stop_vmname parameter to hardstopvm.php. NOTE: some of these details are obtained from third party information.
Metrics
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Citrix | Xencenterweb | All versions |
References
- http://securitytracker.com/id?1022520Broken Link, Third Party Advisory, VDB Entry
- http://www.exploit-db.com/exploits/9106Exploit, Third Party Advisory, VDB Entry
- http://www.securityfocus.com/archive/1/504764Broken Link, Exploit, Third Party Advisory, VDB Entry
- http://www.securityfocus.com/bid/35592Broken Link, Exploit, Third Party Advisory, VDB Entry
- http://www.vupen.com/english/advisories/2009/1814Broken Link, Vendor Advisory
- https://exchange.xforce.ibmcloud.com/vulnerabilities/51576Third Party Advisory, VDB Entry
- http://securitytracker.com/id?1022520Broken Link, Third Party Advisory, VDB Entry
- http://www.exploit-db.com/exploits/9106Exploit, Third Party Advisory, VDB Entry
- http://www.securityfocus.com/archive/1/504764Broken Link, Exploit, Third Party Advisory, VDB Entry
- http://www.securityfocus.com/bid/35592Broken Link, Exploit, Third Party Advisory, VDB Entry
- http://www.vupen.com/english/advisories/2009/1814Broken Link, Vendor Advisory
- https://exchange.xforce.ibmcloud.com/vulnerabilities/51576Third Party Advisory, VDB Entry
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2009-3759?
How severe is CVE-2009-3759?
How do I fix CVE-2009-3759?
Are you affected by CVE-2009-3759?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
