Vulnerabilities (CVE)

Filtered by vendor Citrix Subscribe
Filtered by product Web Interface
Total 4 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2010-4515 1 Citrix 1 Web Interface 2023-12-10 4.3 MEDIUM N/A
Cross-site scripting (XSS) vulnerability in Citrix Web Interface 5.0, 5.1, and 5.3 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors, a different vulnerability than CVE-2007-6477 and CVE-2009-2454.
CVE-2008-6830 1 Citrix 1 Web Interface 2023-12-10 4.0 MEDIUM N/A
The disconnection feature in Citrix Web Interface 5.0 and 5.0.1 for Java Application Servers does not properly terminate a user's web interface session, which allows attackers with access to the same browser instance to gain access to the user's Web Interface session. NOTE: the attacker must also have valid credentials to the Web Interface.
CVE-2009-2454 1 Citrix 1 Web Interface 2023-12-10 4.3 MEDIUM N/A
Cross-site scripting (XSS) vulnerability in Citrix Web Interface 4.6, 5.0, and 5.0.1 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.
CVE-2007-6477 1 Citrix 1 Web Interface 2023-12-10 4.3 MEDIUM N/A
Cross-site scripting (XSS) vulnerability in the on-line help feature in Citrix Web Interface 2.0 and earlier, and NFuse, allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.