Public exploit available
Public proof-of-concept or exploit code exists (ExploitDB / Metasploit / Nuclei).

CVE-2007-6037Cross-site Scripting in Citrix Netscaler

Severity
4.3MEDIUMNVD
EPSS
10.8%
top 6.60%
CISA KEV
Not in KEV
Exploit
PoC available
Public exploit / PoC exists
Timeline
PublishedNov 20
Latest updateMay 1

Description

Cross-site scripting (XSS) vulnerability in ws/generic_api_call.pl in Citrix NetScaler 8.0 build 47.8 allows remote attackers to inject arbitrary web script or HTML via the standalone parameter and other unspecified parameters.

CVSS vector

AV:N/AC:M/C:N/I:P/A:NExploitability: 8.6 | Impact: 2.9

Affected Packages2 packages

🔴Vulnerability Details

1
GHSA
GHSA-wx9x-3hjm-589w: Cross-site scripting (XSS) vulnerability in ws/generic_api_call2022-05-01

💥Exploits & PoCs

1
Exploit-DB
Citrix Netscaler 8.0 build 47.8 - Generic_API_Call.pl Cross-Site Scripting2007-11-19

📋Vendor Advisories

1
Citrix
CVE-2007-6037: Cross-site scripting (XSS) vulnerability in ws/generic_api_call.pl in Citrix NetScaler 8.0 build 47.8 allows remote attackers to inject arbitrary web2007-11-20