Citrix NFuse 1.6 allows remote attackers to bypass authentication and obtain sensitive information by directly calling launch.asp with invalid NFUSE_USER and NFUSE_PASSWORD parameters.
Link | Tags |
---|---|
http://www.securityfocus.com/bid/4142 | vdb entry |
http://marc.info/?l=bugtraq&m=101424947801895&w=2 | mailing list |