CVE-2009-2277
published 2010-04-01CVE-2009-2277: Cross-site scripting (XSS) vulnerability in WebAccess in VMware VirtualCenter 2.0.2 and 2.5 and VMware ESX 3.0.3 and 3.5 allows remote attackers to inject…
PriorityP418medium4.3CVSS 2.0
AVNACMAuNCNIPAN
EPSS
1.66%
73.8th percentile
Cross-site scripting (XSS) vulnerability in WebAccess in VMware VirtualCenter 2.0.2 and 2.5 and VMware ESX 3.0.3 and 3.5 allows remote attackers to inject arbitrary web script or HTML via vectors related to "context data."
Affected
6 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| vmware | esx_server | — | — |
| vmware | esx_server | — | — |
| vmware | esxi | — | — |
| vmware | virtualcenter | — | — |
| vmware | virtualcenter | — | — |
| vmware | vmware_workstation | — | — |
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-5558-3h54-4jfj: Cross-site scripting (XSS) vulnerability in WebAccess in VMware VirtualCenter 2
ghsa_unreviewed·2022-05-02
CVE-2009-2277 [MEDIUM] CWE-79 GHSA-5558-3h54-4jfj: Cross-site scripting (XSS) vulnerability in WebAccess in VMware VirtualCenter 2
Cross-site scripting (XSS) vulnerability in WebAccess in VMware VirtualCenter 2.0.2 and 2.5 and VMware ESX 3.0.3 and 3.5 allows remote attackers to inject arbitrary web script or HTML via vectors related to "context data."
VMware
VMware products address vulnerabilities in WebAccess
vendor_vmware·2010-03-29·CVSS 4.3
CVE-2009-2277 [MEDIUM] VMware products address vulnerabilities in WebAccess
VMSA-2010-0005: VMware products address vulnerabilities in WebAccess
a. WebAccess Context Data Cross-site Scripting Vulnerability A cross-site scripting vulnerability in WebAccess allows for disclosure of sensitive information. The flaw is due to insufficient verification of certain parameters which may lead to redirection of a user's requests. This vulnerability can only be exploited if the attacker tricks the WebAccess user into clicking a malicious link and the attacker has control of a server on the same network as the system where WebAccess is being used.
CVEs: CVE-2009-2277, CVE-2010-0686, CVE-2010-1137, CVE-2010-1193
Affected products: ESXi, VMware Workstation
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
http://lists.vmware.com/pipermail/security-announce/2010/000086.htmlhttp://www.securityfocus.com/bid/39037http://www.vmware.com/security/advisories/VMSA-2010-0005.htmlhttps://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A7080http://lists.vmware.com/pipermail/security-announce/2010/000086.htmlhttp://www.securityfocus.com/bid/39037http://www.vmware.com/security/advisories/VMSA-2010-0005.htmlhttps://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A7080
2010-04-01
Published