PT-2001-1941 · Citrix · Citrix Nfuse
Publicado
2001-10-18
·
Atualizado
2017-10-10
·
CVE-2001-0760
CVSS v2.0
5.0
Média
| Vetor | AV:N/AC:L/Au:N/C:P/I:N/A:N |
Name of the Vulnerable Software and Affected Versions:
Citrix Nfuse version 1.51
Description:
The issue allows remote attackers to obtain the absolute path of the web root via a malformed request to "launch.asp" that does not provide the
session field.Recommendations:
For Citrix Nfuse version 1.51, consider restricting access to the "launch.asp" endpoint until a fix is available, and ensure that all requests to this endpoint provide the required
session field to prevent exploitation.Exploit
Correção
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Identificadores relacionados
Produtos afetados
Citrix Nfuse