Unspecified vulnerability in the Management Interface in VMware ESX Server 2.x up to 2.5.x before 24 December 2005 allows "remote code execution in the Web browser" via unspecified attack vectors, probably related to cross-site scripting (XSS).
The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users.
Link | Tags |
---|---|
http://www.vmware.com/support/kb/enduser/std_adp.php?p_faqid=2001 | patch |
http://www.securityfocus.com/bid/16086 | vdb entry patch |
http://securitytracker.com/id?1015422 | exploit vdb entry patch |
http://secunia.com/advisories/18250 | third party advisory patch vendor advisory |
http://www.vupen.com/english/advisories/2005/3084 | vdb entry vendor advisory |
http://www.osvdb.org/22119 | vdb entry patch |