Citrix Nfuse boilerplate.asp Web Root Disclosure Vulnerability
BID:4382
Info
Citrix Nfuse boilerplate.asp Web Root Disclosure Vulnerability
| Bugtraq ID: | 4382 |
| Class: | Design Error |
| CVE: |
CVE-2002-0503 |
| Remote: | No |
| Local: | Yes |
| Published: | Mar 28 2002 12:00AM |
| Updated: | Jul 11 2009 11:56AM |
| Credit: | Reported by Eric Budke <[email protected]>. |
| Vulnerable: |
Citrix Nfuse 1.5 |
| Not Vulnerable: | |
Discussion
Citrix Nfuse boilerplate.asp Web Root Disclosure Vulnerability
Citrix Nfuse is an application portal server meant to provide the functionality of any application on the server via a web browser. Nfuse works in conjunction with a previously-installed webserver.
It has been reported that a legitimate user of the service, can learn the location of the webroot. Submitting a specially crafted request via boilerplate.asp, could cause the host to return an error message containing the path to the web root.
Citrix Nfuse is an application portal server meant to provide the functionality of any application on the server via a web browser. Nfuse works in conjunction with a previously-installed webserver.
It has been reported that a legitimate user of the service, can learn the location of the webroot. Submitting a specially crafted request via boilerplate.asp, could cause the host to return an error message containing the path to the web root.
Exploit / POC
Citrix Nfuse boilerplate.asp Web Root Disclosure Vulnerability
No exploit code is required.
No exploit code is required.
Solution / Fix
Citrix Nfuse boilerplate.asp Web Root Disclosure Vulnerability
Solution:
Reportedly, more recent versions (Nfuse 1.6) are not vulnerable to this issue. However this has not been confirmed.
Solution:
Reportedly, more recent versions (Nfuse 1.6) are not vulnerable to this issue. However this has not been confirmed.