Cross-site scripting vulnerability in Citrix NFuse 1.6 and earlier does not quote results from the getLastError method, which allows remote attackers to execute script in other clients via the NFuseApplication parameter to (1) launch.jsp or (2) launch.asp.
Citrix NFuse 1.6 may allow remote attackers to list applications without authentication by accessing the applist.asp page.
Citrix NFuse 1.6 allows remote attackers to bypass authentication and obtain sensitive information by directly calling launch.asp with invalid NFUSEUSER and NFUSEPASSWORD parameters.