Citrix Nfuse 1.51 allows remote attackers to obtain the absolute path of the web root via a malformed request to launch.asp that does not provide the session field.
Link | Tags |
---|---|
http://www.securityfocus.com/bid/2956 | exploit vdb entry vendor advisory |
https://exchange.xforce.ibmcloud.com/vulnerabilities/6786 | vdb entry |
http://www.securityfocus.com/archive/1/194449 | mailing list vendor advisory |
http://www.securityfocus.com/archive/1/194522 | mailing list vendor advisory |