PT-2001-1941 · Citrix · Citrix Nfuse

Published

2001-10-18

·

Updated

2017-10-10

·

CVE-2001-0760

CVSS v2.0

5.0

Medium

VectorAV:N/AC:L/Au:N/C:P/I:N/A:N
Name of the Vulnerable Software and Affected Versions: Citrix Nfuse version 1.51
Description: The issue allows remote attackers to obtain the absolute path of the web root via a malformed request to "launch.asp" that does not provide the session field.
Recommendations: For Citrix Nfuse version 1.51, consider restricting access to the "launch.asp" endpoint until a fix is available, and ensure that all requests to this endpoint provide the required session field to prevent exploitation.

Exploit

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

CVE-2001-0760

Affected Products

Citrix Nfuse