PT-2001-1941 · Citrix · Citrix Nfuse
Published
2001-10-18
·
Updated
2017-10-10
·
CVE-2001-0760
CVSS v2.0
5.0
Medium
| Vector | AV:N/AC:L/Au:N/C:P/I:N/A:N |
Name of the Vulnerable Software and Affected Versions:
Citrix Nfuse version 1.51
Description:
The issue allows remote attackers to obtain the absolute path of the web root via a malformed request to "launch.asp" that does not provide the
session field.Recommendations:
For Citrix Nfuse version 1.51, consider restricting access to the "launch.asp" endpoint until a fix is available, and ensure that all requests to this endpoint provide the required
session field to prevent exploitation.Exploit
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Citrix Nfuse