Citrix Published Applications Remote Enumeration

medium Nessus Plugin ID 11138

Synopsis

The remote Citrix service is affected by an information disclosure vulnerability.

Description

It is possible for a remote attacker to enumerate published applications that are allowed on the affected Citrix server.

Solution

Consult the advisory referenced above for tips about securing the service.

See Also

https://packetstormsecurity.com/files/29932/hackingcitrix.txt.html

https://seclists.org/bugtraq/2002/Sep/292

Plugin Details

Severity: Medium

ID: 11138

File Name: citrix.nasl

Version: 1.26

Type: remote

Family: Misc.

Published: 10/9/2002

Updated: 12/22/2020

Supported Sensors: Nessus

Risk Information

CVSS v2

Risk Factor: Medium

Base Score: 5

Temporal Score: 3.7

Vector: CVSS2#AV:N/AC:L/Au:N/C:P/I:N/A:N

Vulnerability Information

Exploit Available: true

Exploit Ease: No exploit is required

Reference Information

BID: 5817