PT-2002-1555 · Citrix · Citrix Nfuse

Published

2002-06-11

·

Updated

2008-09-05

·

CVE-2002-0504

CVSS v2.0

7.5

High

VectorAV:N/AC:L/Au:N/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions Citrix NFuse versions 1.6 and earlier
Description The issue is related to a cross-site scripting vulnerability. It does not properly quote results from the getLastError method, allowing remote attackers to execute script in other clients. This can be achieved via the NFuse Application parameter to launch.jsp or launch.asp API endpoints.
Recommendations For Citrix NFuse versions 1.6 and earlier, at the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

CVE-2002-0504

Affected Products

Citrix Nfuse