First published: Sat Dec 03 2005(Updated: )
Cross-site scripting (XSS) vulnerability in the login form in Citrix MetaFrame Secure Access Manager 2.0 through 2.2 and NFuse Elite 1.0 allows remote attackers to inject arbitrary web script or HTML via the username field.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Citrix MetaFrame Secure Access Manager | =2.0 | |
Citrix MetaFrame Secure Access Manager | =2.2 | |
Citrix MetaFrame Secure Access Manager | =2.1 | |
Citrix NFuse | =1.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2005-3971 is classified as a medium severity vulnerability due to its potential to allow unauthorized access through cross-site scripting.
To mitigate CVE-2005-3971, upgrade to a patched version of Citrix MetaFrame Secure Access Manager or NFuse that addresses the XSS vulnerability.
CVE-2005-3971 allows attackers to inject arbitrary web scripts or HTML, potentially leading to session hijacking or information theft.
CVE-2005-3971 affects Citrix MetaFrame Secure Access Manager versions 2.0 to 2.2 and Citrix NFuse Elite version 1.0.
There are no official workarounds for CVE-2005-3971; updating to fixed software versions is recommended for security.