CVE-2005-3620
published 2005-12-31CVE-2005-3620: The management interface for VMware ESX Server 2.0.x before 2.0.2 patch 1, 2.1.x before 2.1.3 patch 1, and 2.x before 2.5.3 patch 2 records passwords in…
PriorityP49low2.1CVSS 2.0
AVLACLAuNCPINAN
EPSS
0.47%
37.8th percentile
The management interface for VMware ESX Server 2.0.x before 2.0.2 patch 1, 2.1.x before 2.1.3 patch 1, and 2.x before 2.5.3 patch 2 records passwords in cleartext in URLs that are stored in world-readable web server log files, which allows local users to gain privileges.
Affected
4 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| emc | vmware_server | <= 1.0.4_build_56528 | — |
| vmware | esx | >= 2.0.1 < 2.0.2 | 2.0.2 |
| vmware | esx | >= 2.1.1 < 2.1.3 | 2.1.3 |
| vmware | esx | >= 2.5.2 < 2.5.3 | 2.5.3 |
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-p46c-qg3j-fgr9: The management interface for VMware ESX Server 2
ghsa_unreviewed·2022-05-01
CVE-2005-3620 [LOW] GHSA-p46c-qg3j-fgr9: The management interface for VMware ESX Server 2
The management interface for VMware ESX Server 2.0.x before 2.0.2 patch 1, 2.1.x before 2.1.3 patch 1, and 2.x before 2.5.3 patch 2 records passwords in cleartext in URLs that are stored in world-readable web server log files, which allows local users to gain privileges.
GHSA
GHSA-mr86-rf34-87mq: EMC VMware Server before 1
ghsa_unreviewed·2022-05-01·CVSS 2.1
CVE-2007-5024 [LOW] GHSA-mr86-rf34-87mq: EMC VMware Server before 1
EMC VMware Server before 1.0.4 Build 56528 writes passwords in cleartext to unspecified log files, which allows local users to obtain sensitive information by reading these files, a different vulnerability than CVE-2005-3620.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
http://kb.vmware.com/kb/2118366http://secunia.com/advisories/21230http://www.corsaire.com/advisories/c051114-003.txthttp://www.kb.cert.org/vuls/id/822476http://www.securityfocus.com/archive/1/441727/100/100/threadedhttp://www.securityfocus.com/archive/1/441825/100/100/threadedhttp://www.securityfocus.com/bid/19249http://www.vupen.com/english/advisories/2006/3075https://exchange.xforce.ibmcloud.com/vulnerabilities/28112http://kb.vmware.com/kb/2118366http://secunia.com/advisories/21230http://www.corsaire.com/advisories/c051114-003.txthttp://www.kb.cert.org/vuls/id/822476http://www.securityfocus.com/archive/1/441727/100/100/threadedhttp://www.securityfocus.com/archive/1/441825/100/100/threadedhttp://www.securityfocus.com/bid/19249http://www.vupen.com/english/advisories/2006/3075https://exchange.xforce.ibmcloud.com/vulnerabilities/28112
2005-12-31
Published