CVE-2005-3619
published 2005-12-31CVE-2005-3619: Cross-site scripting (XSS) vulnerability in the management interface for VMware ESX 2.5.x before 2.5.2 upgrade patch 2, 2.1.x before 2.1.2 upgrade patch 6, and…
PriorityP419medium6.8CVSS 2.0
AVNACMAuNCPIPAP
EPSS
1.42%
70.1th percentile
Cross-site scripting (XSS) vulnerability in the management interface for VMware ESX 2.5.x before 2.5.2 upgrade patch 2, 2.1.x before 2.1.2 upgrade patch 6, and 2.0.x before 2.0.1 upgrade patch 6 allows remote attackers to inject arbitrary web script or HTML via messages that are not sanitized when viewing syslog log files.
Affected
10 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| vmware | esx | — | — |
| vmware | esx | — | — |
| vmware | esx | — | — |
| vmware | esx | — | — |
| vmware | esx | — | — |
| vmware | esx | — | — |
| vmware | esx | — | — |
| vmware | esx | >= 2.0.1 < 2.0.2 | 2.0.2 |
| vmware | esx | >= 2.1.1 < 2.1.3 | 2.1.3 |
| vmware | esx | >= 2.5.2 < 2.5.3 | 2.5.3 |
CVSS provenance
nvdv2.06.8MEDIUMAV:N/AC:M/Au:N/C:P/I:P/A:P
vendor_redhat5.0MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-jppx-j8c9-3cxq: Cross-site scripting (XSS) vulnerability in the management interface for VMware ESX 2
ghsa_unreviewed·2022-05-01
CVE-2005-3619 [MEDIUM] GHSA-jppx-j8c9-3cxq: Cross-site scripting (XSS) vulnerability in the management interface for VMware ESX 2
Cross-site scripting (XSS) vulnerability in the management interface for VMware ESX 2.5.x before 2.5.2 upgrade patch 2, 2.1.x before 2.1.2 upgrade patch 6, and 2.0.x before 2.0.1 upgrade patch 6 allows remote attackers to inject arbitrary web script or HTML via messages that are not sanitized when viewing syslog log files.
GHSA
GHSA-6f84-r44w-9f3r: VMware ESX Server 2
ghsa_unreviewed·2022-05-01·CVSS 6.8
CVE-2006-2481 [MEDIUM] GHSA-6f84-r44w-9f3r: VMware ESX Server 2
VMware ESX Server 2.0.x before 2.0.2 and 2.x before 2.5.2 patch 4 stores authentication credentials in base 64 encoded format in the vmware.mui.kid and vmware.mui.sid cookies, which allows attackers to gain privileges by obtaining the cookies using attacks such as cross-site scripting (CVE-2005-3619).
GHSA
GHSA-h6c2-g6q9-7g8w: Cross-site request forgery (CSRF) vulnerability in the management interface for VMware ESX Server 2
ghsa_unreviewed·2022-05-01·CVSS 6.8
CVE-2005-3618 [MEDIUM] GHSA-h6c2-g6q9-7g8w: Cross-site request forgery (CSRF) vulnerability in the management interface for VMware ESX Server 2
Cross-site request forgery (CSRF) vulnerability in the management interface for VMware ESX Server 2.0.x before 2.0.2 patch 1, 2.1.x before 2.1.3 patch 1, and 2.x before 2.5.3 patch 2 allows allows remote attackers to perform unauthorized actions as the administrator via URLs, as demonstrated using the setUsr operation to change a password. NOTE: this issue can be leveraged with CVE-2005-3619 to automatically perform the attacks.
Red Hat
fastjar: directory traversal vulnerabilities
vendor_redhat·2010-06-06·CVSS 5.0
CVE-2010-0831 [MEDIUM] fastjar: directory traversal vulnerabilities
fastjar: directory traversal vulnerabilities
Directory traversal vulnerability in the extract_jar function in jartool.c in FastJar 0.98 allows remote attackers to create or overwrite arbitrary files via a .. (dot dot) in a non-initial pathname component in a filename within a .jar archive, a related issue to CVE-2005-1080. NOTE: this vulnerability exists because of an incomplete fix for CVE-2006-3619.
Statement: The Red Hat Security Response Team has rated this issue as having low security impact, a future update may address this flaw.
Package: gcc (Red Hat Enterprise Linux 4) - Will not fix
Package: gcc4 (Red Hat Enterprise Linux 4) - Will not fix
Package: gcc44 (Red Hat Enterprise Linux 5) - Not affected
Package: gcc (Red Hat Enterprise Linux 6) - Not affected
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
http://www.corsaire.com/advisories/c051114-002.txthttp://www.securityfocus.com/archive/1/435610/100/0/threadedhttp://www.securityfocus.com/archive/1/435888/100/0/threadedhttp://www.corsaire.com/advisories/c051114-002.txthttp://www.securityfocus.com/archive/1/435610/100/0/threadedhttp://www.securityfocus.com/archive/1/435888/100/0/threaded
2005-12-31
Published