CVE-2002-0502
Citrix NFuse 1.6 - Unauthenticated Application Listing via applist.asp
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2002-0502. PoCs published by Ian Vitek.
AI-analyzed exploit summary The code is a scanner for enumerating Citrix published applications via UDP port 1604, leveraging an information disclosure vulnerability in Citrix Nfuse. It includes tools for scanning, proxying, and connecting to published applications.
Description
Citrix NFuse 1.6 may allow remote attackers to list applications without authentication by accessing the applist.asp page.
Exploits (1)
exploitdb
SCANNER
VERIFIED
by Ian Vitek · perlremotewindows
https://www.exploit-db.com/exploits/21235
The code is a scanner for enumerating Citrix published applications via UDP port 1604, leveraging an information disclosure vulnerability in Citrix Nfuse. It includes tools for scanning, proxying, and connecting to published applications.
Classification
Scanner 90%
Attack Type
Info Leak
Complexity
Moderate
Reliability
Reliable
Target:
Citrix Nfuse (version not specified)
No auth needed
Prerequisites:
Network access to UDP port 1604 on the target · Citrix Nfuse server with published applications
devstral-2 · analyzed Feb 16, 2026
Full analysis →
References (4)
Core 4
Core References
Third Party Advisory, VDB Entry vdb-entry
x_refsource_xf
https://exchange.xforce.ibmcloud.com/vulnerabilities/7984
Vendor Advisory mailing-list
x_refsource_bugtraq
http://www.securityfocus.com/archive/1/251737
Vendor Advisory mailing-list
x_refsource_bugtraq
http://www.securityfocus.com/archive/1/251923
Vendor Advisory vdb-entry
x_refsource_bid
http://www.securityfocus.com/bid/3926
Scores
EPSS
0.0359
EPSS Percentile
87.9%
Details
Status
published
Products (1)
citrix/nfuse
1.6
Published
Aug 12, 2002
Tracked Since
Feb 18, 2026