PT-2006-3429 · Vmware · Vmware Esx Server
Published
2006-07-31
·
Updated
2018-10-30
·
CVE-2006-2481
CVSS v2.0
5.0
Medium
| Vector | AV:N/AC:L/Au:N/C:P/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
VMware ESX Server versions 2.0.x before 2.0.2
VMware ESX Server versions 2.x before 2.5.2 patch 4
Description
The issue allows attackers to gain privileges by obtaining authentication credentials stored in base 64 encoded format in the
vmware.mui.kid and vmware.mui.sid cookies. This can be achieved through attacks such as cross-site scripting.Recommendations
For versions 2.0.x before 2.0.2, update to version 2.0.2 or later.
For versions 2.x before 2.5.2 patch 4, apply patch 4 or later to version 2.5.2.
Exploit
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Vmware Esx Server