Citrix Multiple Applications Login Form Cross-Site Scripting Vulnerability
BID:15664
Info
Citrix Multiple Applications Login Form Cross-Site Scripting Vulnerability
| Bugtraq ID: | 15664 |
| Class: | Input Validation Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Dec 01 2005 12:00AM |
| Updated: | Dec 01 2005 12:00AM |
| Credit: | The vendor disclosed this issue. |
| Vulnerable: |
Citrix NFuse Elite 1.0 Citrix Metaframe Secure Access Manager 2.2 Citrix Metaframe Secure Access Manager 2.1 Citrix Metaframe Secure Access Manager 2.0 |
| Not Vulnerable: | |
Discussion
Citrix Multiple Applications Login Form Cross-Site Scripting Vulnerability
Citrix MetaFrame Secure Access Manager and Citrix NFuse Elite are prone to a cross-site scripting vulnerability. These issues are due to a failure in the applications to properly sanitize user-supplied input.
An attacker may leverage these issues to have arbitrary script code executed in the browser of an unsuspecting user in the context of the affected site. This may facilitate the theft of cookie-based authentication credentials as well as other attacks.
Citrix MetaFrame Secure Access Manager and Citrix NFuse Elite are prone to a cross-site scripting vulnerability. These issues are due to a failure in the applications to properly sanitize user-supplied input.
An attacker may leverage these issues to have arbitrary script code executed in the browser of an unsuspecting user in the context of the affected site. This may facilitate the theft of cookie-based authentication credentials as well as other attacks.
Exploit / POC
Citrix Multiple Applications Login Form Cross-Site Scripting Vulnerability
No exploit is required.
No exploit is required.
Solution / Fix
Citrix Multiple Applications Login Form Cross-Site Scripting Vulnerability
Solution:
The vendor has released a hotfix addressing this issue for MetaFrame Secure Access Manager. Users are advised to contact the vendor for more information regarding this issue for NFuse Elite.
Citrix Metaframe Secure Access Manager 2.0
Citrix Metaframe Secure Access Manager 2.1
Citrix Metaframe Secure Access Manager 2.2
Solution:
The vendor has released a hotfix addressing this issue for MetaFrame Secure Access Manager. Users are advised to contact the vendor for more information regarding this issue for NFuse Elite.
Citrix Metaframe Secure Access Manager 2.0
-
Citrix MSAME201W010
http://www.citrix.com/
Citrix Metaframe Secure Access Manager 2.1
-
Citrix MSAME201W010
http://www.citrix.com/
Citrix Metaframe Secure Access Manager 2.2
-
Citrix MSAME201W010
http://www.citrix.com/
References
Citrix Multiple Applications Login Form Cross-Site Scripting Vulnerability
References:
References: