Citrix NetScaler AppFirewall, as used in NetScaler 10.5, allows remote attackers to bypass intended firewall restrictions via a crafted Content-Type header, as demonstrated by the application/octet-stream and text/xml Content-Types.
The product does not restrict or incorrectly restricts access to a resource from an unauthorized actor.
Link | Tags |
---|---|
http://securitytracker.com/id/1031928 | vdb entry |
https://www.exploit-db.com/exploits/36369/ | exploit |
http://seclists.org/fulldisclosure/2015/Mar/95 | mailing list exploit |