Back

CVE-2002-0504

Cross-site scripting vulnerability in Citrix NFuse 1.6 and earlier does not quote results from the getLastError method, which allows remote attackers to execute script in other clients via the NFuse_Application parameter to (1) launch.jsp or (2) launch.asp.

Published: Aug 12, 2002 Modified: Jun 16, 2026

CVSS Metrics

Affected Products (2)

Vendor Product Version
citrix nfuse *
citrix nfuse 1.51

GitHub Security Advisory GHSA-rvg3-96rj-365f

Cross-site scripting vulnerability in Citrix NFuse 1.6 and earlier does not quote results from...

Risk Scores

CVSS Score 7.5 / 10
EPSS Score 7.94%

Top 6% most likely to be exploited

Threat Score 32.4 / 100

Data Sources

NVD EPSS GitHub