Search: Home Bugtraq Vulnerabilities Mailing Lists Jobs Tools Beta Programs

Citrix Nfuse Published Applications Information Leak Vulnerability

Citrix Nfuse is an application portal server meant to provide the functionality of any application on the server via a web browser. Nfuse works in conjunction with a previously-installed webserver.

If a request for 'applist.asp' is submitted without authentication, Nfuse reportedly will disclose a list of all published applications.

There have been reports that this issue could not be reproduced.

* The result of this issue is likely due to a session cookie which is not deleted until all browser sessions are shut down. If the user properly logs out, the session cookie is modified such that they must re-authenticate.







 

Privacy Statement
Copyright 2008, SecurityFocus