361,800
Total CVEs
26,223
Critical
85,816
High
1,626
CISA KEV
0
This Week
709 results · Page 29/29
Citrix NFuse 1.6 may allow remote attackers to list applications without authentication by accessing the applist.asp page.
citrix
Cross-site scripting vulnerability in Citrix NFuse 1.6 and earlier does not quote results from the getLastError method, which allows remote attackers to execute script in other clients via the NFuse_Application parameter to (1) launch.jsp or (2) launch.asp.
citrix
Directory traversal vulnerability in boilerplate.asp for Citrix NFuse 1.5 allows remote authenticated users to read arbitrary files via a .. (dot dot) in the NFuse_Template parameter.
citrix
Citrix NFuse 1.6 allows remote attackers to bypass authentication and obtain sensitive information by directly calling launch.asp with invalid NFUSE_USER and NFUSE_PASSWORD parameters.
citrix