S-194: Citrix MetaFrame Web Manager 'login.asp' Vulnerability


 
Thread Tools Search this Thread
Special Forums Cybersecurity Security Advisories (RSS) S-194: Citrix MetaFrame Web Manager 'login.asp' Vulnerability
# 1  
Old 02-25-2008
S-194: Citrix MetaFrame Web Manager 'login.asp' Vulnerability

Citrix MetaFrame Web Manager is prone to a cross-site scripting vulnerability because it fails to properly sanitize user-supplied input. The risk is MEDIUM. An attacker may leverage this issue to execute arbitrary script code in the browser of an unsuspecting user in the context of the affected site. This may allow the attacker to steal cookie-based authentication credentials and to launch other attacks.


More...
Login or Register to Ask a Question

Previous Thread | Next Thread

3 More Discussions You Might Find Interesting

1. Web Development

ASP.NET 5 Application on Centos OS7 Web Hosting Server

Hi All, Frankly I'm new to Linux Environment. While we are trying to Host an ASP.NET 5 Web Application on Centos OS7 Web hosting Server. There were couple of steps which we are supposed to go through, please see this link - We are stuck at Create a Container & then Running the Container,... (1 Reply)
Discussion started by: John Fredric
1 Replies

2. Cybersecurity

APACHE: Tie in Web Page login with server login

Hello, I have created a web page on a server using apache and added .htaccess and .htpasswd in the folder for authentification. I was wondering if there was anyway to tie-in the login for this page with the login used to logon to the server. i.e. the same login info. is used for both, when... (1 Reply)
Discussion started by: WhotheWhat
1 Replies

3. Solaris

How to install citrix metaframe server in Solairs 9 and 10,

How to install citrix metaframe server in Solairs 9 and 10, Plese help me if anybody having instllation procedure. your help greatly appreciated. Thanks & Regards Durgaprasad (0 Replies)
Discussion started by: durgaprasadr13
0 Replies
Login or Register to Ask a Question
pdweb(1M)																 pdweb(1M)

NAME
pdweb - start the HP-UX Peripheral Device tool, part of the System Management Homepage Web interface. SYNOPSIS
Path: DESCRIPTION
The HP-UX Peripheral Device tool (pdweb) can be used to easily and quickly view I/O devices and OLRAD cards. It helps manage hot pluggable PCI slots on systems that support adding and replacing cards without rebooting. On all HP-UX systems, will display the I/O devices and can be used to (re)create device files for a selected device. The HP-UX Peripheral Device tool user interface uses a Web browser. Executing the command, with DISPLAY variable set and without any options performs the following tasks: o start the System Management Homepage Web server and o start a Web client (browser) An attempt will be made to connect to the browser specified with the BROWSER environment variable, or Mozilla, or Netscape. The Web browser will be displayed on the X server defined by the DISPLAY environment variable. If a running browser is found, it will be used, otherwise a new session will be initiated. This will only happen if the browser process is running on the same system used to exectue the pdweb command (defined by the DISPLAY variable), unless the option is used. Options The recognizes the following options: Opens the terminal interface for Cards and Devices regardless of the current setting of the DISPLAY environment variable. Forces a client browser to be used in less secure ways. Two security features are overridden by the option. The option forces the client browser to be used or started, even if the X-traffic between the X-server and the Mozilla browser is not secure. When is invoked by the option is used. Only a priviledged user (root) can execute When used with the option, a temporary login bypass key will be generated. The bypass key allows the user to access the Web interface without having to provide login information again. Only use this option if you are sure the network traffic is secure between the host where Mozilla is running, and the host in the DISPLAY variable. The browser uses URL http://hostname:2301/ and you may paste this into any browser if a browser does open with the pdweb command. Online Help Once the HP-UX Peripheral Device tool is started, the online help provides details on how to use the tool. RETURN VALUES
Upon completion, returns one of the following values: Successful. An error occurred. AUTHORS
pdweb was developed by Hewlett-Packard SEE ALSO
hpsmh(1M), smhstartconfig(1M), olrad(1M), ioscan(1M), insf(1M) pdweb(1M)