Citrix Nfuse Webroot Disclosure Vulnerability
BID:2956
Info
Citrix Nfuse Webroot Disclosure Vulnerability
| Bugtraq ID: | 2956 |
| Class: | Failure to Handle Exceptional Conditions |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Jul 02 2001 12:00AM |
| Updated: | Jul 02 2001 12:00AM |
| Credit: | Posted to the bugtraq mailing list on July 2, 2001 by sween <[email protected]>. |
| Vulnerable: |
Citrix Nfuse 1.51 |
| Not Vulnerable: | |
Discussion
Citrix Nfuse Webroot Disclosure Vulnerability
Citrix Nfuse is an application portal server meant to provide the functionality of any application on the server via a web browser. Nfuse works in conjunction with a previously-installed webserver.
It has been reported that a remote attacker can learn the location of the webroot simply by submitting a request to the launcher application without specifying the additional required information. This has been reported to not be reliably replicable.
Citrix Nfuse is an application portal server meant to provide the functionality of any application on the server via a web browser. Nfuse works in conjunction with a previously-installed webserver.
It has been reported that a remote attacker can learn the location of the webroot simply by submitting a request to the launcher application without specifying the additional required information. This has been reported to not be reliably replicable.
Exploit / POC
Citrix Nfuse Webroot Disclosure Vulnerability
This vulnerability can be exploited by making the following request to the affected system:
http://target/path/launch.asp?
This vulnerability can be exploited by making the following request to the affected system:
http://target/path/launch.asp?