Vulnerability Name: | CVE-2010-1137 (CCN-57310) | ||||||||
Assigned: | 2010-03-29 | ||||||||
Published: | 2010-03-29 | ||||||||
Updated: | 2017-09-19 | ||||||||
Summary: | Cross-site scripting (XSS) vulnerability in WebAccess in VMware VirtualCenter 2.0.2 and 2.5 and VMware ESX 3.0.3 and 3.5, and the Server Console in VMware Server 1.0, allows remote attackers to inject arbitrary web script or HTML via the name of a virtual machine. | ||||||||
CVSS v3 Severity: | 5.3 Medium (CCN CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N)
| ||||||||
CVSS v2 Severity: | 4.3 Medium (CVSS v2 Vector: AV:N/AC:M/Au:N/C:N/I:P/A:N) 3.7 Low (Temporal CVSS v2 Vector: AV:N/AC:M/Au:N/C:N/I:P/A:N/E:H/RL:OF/RC:C)
3.7 Low (CCN Temporal CVSS v2 Vector: AV:N/AC:M/Au:N/C:N/I:P/A:N/E:H/RL:OF/RC:C)
| ||||||||
Vulnerability Type: | CWE-79 | ||||||||
Vulnerability Consequences: | Gain Access | ||||||||
References: | Source: MITRE Type: CNA CVE-2010-1137 Source: CCN Type: VMSA-2010-0005 VMware products address vulnerabilities in WebAccess Source: MLIST Type: Patch, Vendor Advisory [security-announce] 20100329 VMSA-2010-0005 VMware products address vulnerabilities in WebAccess Source: CCN Type: SA39171 VMware ESX WebAccess Two Vulnerabilities Source: CCN Type: SA39172 VMware Server Console Script Insertion Vulnerability Source: GENTOO Type: UNKNOWN GLSA-201209-25 Source: CCN Type: SECTRACK ID: 1023769 VMware Server Input Validation Flaws in WebAccess Permit Cross-Site Scripting Attacks Source: CCN Type: OSVDB ID: 63319 VMware Server Console Virtual Machine Name XSS Source: BID Type: UNKNOWN 39037 Source: CCN Type: BID-39037 RETIRED: VMware WebAccess Multiple Vulnerabilities Source: CCN Type: BID-39104 VMware WebAccess Virtual Machine Name Cross-site Scripting Vulnerability Source: SECTRACK Type: UNKNOWN 1023769 Source: CONFIRM Type: Patch, Vendor Advisory http://www.vmware.com/security/advisories/VMSA-2010-0005.html Source: XF Type: UNKNOWN vmware-virtualmachine-xss(57310) Source: OVAL Type: UNKNOWN oval:org.mitre.oval:def:6863 | ||||||||
Vulnerable Configuration: | Configuration 1: Configuration 2: Configuration 3: Configuration CCN 1: Denotes that component is vulnerable | ||||||||
Oval Definitions | |||||||||
| |||||||||
BACK |