CVE-2006-2481
published 2006-07-31CVE-2006-2481: VMware ESX Server 2.0.x before 2.0.2 and 2.x before 2.5.2 patch 4 stores authentication credentials in base 64 encoded format in the vmware.mui.kid and…
PriorityP430medium5CVSS 2.0
AVNACLAuNCPINAN
EXPLOIT
EPSS
7.06%
93.5th percentile
VMware ESX Server 2.0.x before 2.0.2 and 2.x before 2.5.2 patch 4 stores authentication credentials in base 64 encoded format in the vmware.mui.kid and vmware.mui.sid cookies, which allows attackers to gain privileges by obtaining the cookies using attacks such as cross-site scripting (CVE-2005-3619).
Affected
7 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| vmware | esx | — | — |
| vmware | esx | — | — |
| vmware | esx | — | — |
| vmware | esx | — | — |
| vmware | esx | — | — |
| vmware | esx | — | — |
| vmware | esx | — | — |
CVEs like this are exactly what “Exploited This Week” covers.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
No detection rules found.
No writeups or analysis indexed.
http://kb.vmware.com/kb/2118366http://secunia.com/advisories/21230http://www.corsaire.com/advisories/c060512-001.txthttp://www.securityfocus.com/archive/1/441728/100/100/threadedhttp://www.securityfocus.com/archive/1/441825/100/100/threadedhttp://www.securityfocus.com/bid/19249http://www.vupen.com/english/advisories/2006/3075http://kb.vmware.com/kb/2118366http://secunia.com/advisories/21230http://www.corsaire.com/advisories/c060512-001.txthttp://www.securityfocus.com/archive/1/441728/100/100/threadedhttp://www.securityfocus.com/archive/1/441825/100/100/threadedhttp://www.securityfocus.com/bid/19249http://www.vupen.com/english/advisories/2006/3075
2006-07-31
Published