PT-2002-1555 · Citrix · Citrix Nfuse

Publicado

2002-06-11

·

Atualizado

2008-09-05

·

CVE-2002-0504

CVSS v2.0

7.5

Alta

VetorAV:N/AC:L/Au:N/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions Citrix NFuse versions 1.6 and earlier
Description The issue is related to a cross-site scripting vulnerability. It does not properly quote results from the getLastError method, allowing remote attackers to execute script in other clients. This can be achieved via the NFuse Application parameter to launch.jsp or launch.asp API endpoints.
Recommendations For Citrix NFuse versions 1.6 and earlier, at the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Identificadores relacionados

CVE-2002-0504

Produtos afetados

Citrix Nfuse