HIGH
Cross-site scripting vulnerability in Citrix NFuse 1.6 and earlier does not quote results from the getLastError method, which allows remote attackers to execute script in other clients via the NFuse_Application parameter to (1) launch.jsp or (2) launch.asp
Published Jun 11, 2002
7.5
HIGHCVSS 2.0
EPSS 7.94%
Description
Affected products
Remediation
Metrics
References (3)
Change history (0)
No recorded changes yet.