[23940] in bugtraq
Citrix NFuse 1.6
daemon@ATHENA.MIT.EDU (Tom.Lyne@kamino.com)
Tue Jan 22 15:43:29 2002
From: Tom.Lyne@kamino.com
To: bugtraq@securityfocus.com
Message-ID: <OF069C1236.7111163A-ON80256B49.005754AD@kamino.com>
Date: Tue, 22 Jan 2002 15:57:56 +0000
MIME-Version: 1.0
Content-type: text/plain; charset=us-ascii
Dear Reader,
It seems if you go to an NFuse servers 'applist.asp' page without
first authenticating it reveals a list of all the applications that are
configured as published applications. Seems like an easily preventable
information leak from a default setup,
Rgds,
Tom Lyne