Path traversal in Citrix NetScaler Application Delivery Controller - CVE-2019-19781
Published: January 14, 2020 / Updated: June 17, 2021
Vulnerability details
The vulnerability allows a remote attacker to perform directory traversal attacks.
The vulnerability exists due to input validation error when processing directory traversal sequences in Citrix NetScaler. A remote attacker can send a specially crafted HTTP request and read arbitrary files or execute commands on the system.
Successful exploitation of the vulnerability may allow remote code execution.
Affected software
How to mitigate CVE-2019-19781
Links to Public Exploits and PoC-codes
- Exploit #5811 - Citrix Application Delivery Controller and Citrix Gateway - Remote Code Execution (PoC) (June 17, 2021)
- Exploit #5810 - Citrix Application Delivery Controller and Citrix Gateway - Remote Code Execution (June 17, 2021)
- Exploit #5809 - Citrix Application Delivery Controller and Gateway 10.5 - Remote Code Execution (Metasploit) (June 17, 2021)
- Exploit #5804 - Citrix Application Delivery Controller (ADC) and Gateway 13.0 - Path Traversal (June 17, 2021)
- Exploit #5378 - Citrix ADC (NetScaler) Directory Traversal RCE (May 9, 2021)
- Exploit #3675 - CVE-2019-19781 (Shitrix : CVE-2019-19781 - Remote Code Execution on Citrix ADC Netscaler exploit ) (July 30, 2020)
- Exploit #2657 - Remote-Code-Execution-Exploit-for-Citrix-Application-Delivery-Controller-and-Citrix-Gateway-CVE-201 (This document explain Remote Code Execution Exploit for Citrix Application Delivery Controller and Citrix Gateway [CVE-2019-19781]) (May 12, 2020)
- Exploit #2193 - citrix_dir_traversal_rce (The exploitation module for the CVE-2019-19781 #Shitrix (Vulnerability in Citrix Application Delivery Controller and Citrix Gateway).) (March 18, 2020)
- Exploit #2200 - CVE-2019-19781 (CVE-2019-19781 - Remote Code Execution on Citrix ADC Netscaler exploit) (March 18, 2020)
- Exploit #2195 - citrix.sh (CVE-2019-19781 bash exploit ) (March 18, 2020)
- Exploit #2191 - CitrixHoneypot (Detect and log CVE-2019-19781 scan and exploitation attempts.) (March 18, 2020)
- Exploit #98 - Citrix ADC (NetScaler) Directory Traversal Scanner (March 18, 2020)
- Exploit #1495 - Citrix ADC (NetScaler) Directory Traversal RCE (March 18, 2020)
- Exploit #279 - CVE-2019-19781 (Python CVE-2019-19781 exploit) (March 18, 2020)
- Exploit #278 - cve-2019-19781 (This is a tool published for the Citrix ADC (NetScaler) vulnerability. We are only disclosing this due to others publishing the exploit code first.) (March 18, 2020)
- Exploit #277 - Shitrix-CVE-2019-19781 (My working exploit script for Shitrix (CVE-2019-19781)) (March 18, 2020)
- Exploit #276 - CVE-2019-19781 (Remote Code Execution Exploit for Citrix Application Delivery Controller and Citrix Gateway [ CVE-2019-19781 ]) (March 18, 2020)
- Exploit #275 - CVE-2020-0601 (Remote Code Execution Exploit ) (March 18, 2020)
- Exploit #274 - Exploits_CVE-2019-19781 (All Working Exploits) (March 18, 2020)
- Exploit #273 - CVE-2019-19781 (Remote Code Execution Exploit for Citrix Application Delivery Controller and Citrix Gateway [ CVE-2019-19781 ]) (March 18, 2020)
External References
- http://packetstormsecurity.com/files/155904/Citrix-Application-Delivery-Controller-Gateway-Remote-Code-Execution.html
- http://packetstormsecurity.com/files/155905/Citrix-Application-Delivery-Controller-Gateway-Remote-Code-Execution-Traversal.html
- http://packetstormsecurity.com/files/155930/Citrix-Application-Delivery-Controller-Gateway-10.5-Remote-Code-Execution.html
- https://badpackets.net/over-25000-citrix-netscaler-endpoints-vulnerable-to-cve-2019-19781/
- https://forms.gle/eDf3DXZAv96oosfj6
- https://support.citrix.com/article/CTX267027
- https://twitter.com/bad_packets/status/1215431625766424576
- https://www.kb.cert.org/vuls/id/619785
- https://www.ptsecurity.com/ww-en/about/news/citrix-vulnerability-allows-criminals-to-hack-networks-of-80000-companies/