CVE-2010-0686
published 2010-04-01CVE-2010-0686: WebAccess in VMware VirtualCenter 2.0.2 and 2.5, VMware Server 2.0, and VMware ESX 3.0.3 and 3.5 allows remote attackers to leverage proxy-server functionality…
PriorityP335high7.5CVSS 2.0
AVNACLAuNCPIPAP
EPSS
2.18%
80.3th percentile
WebAccess in VMware VirtualCenter 2.0.2 and 2.5, VMware Server 2.0, and VMware ESX 3.0.3 and 3.5 allows remote attackers to leverage proxy-server functionality to spoof the origin of requests via unspecified vectors, related to a "URL forwarding vulnerability."
Affected
7 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| vmware | esx_server | — | — |
| vmware | esx_server | — | — |
| vmware | esxi | — | — |
| vmware | server | — | — |
| vmware | virtualcenter | — | — |
| vmware | virtualcenter | — | — |
| vmware | vmware_workstation | — | — |
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
VMware
VMware products address vulnerabilities in WebAccess
vendor_vmware·2010-03-29·CVSS 4.3
CVE-2009-2277 [MEDIUM] VMware products address vulnerabilities in WebAccess
VMSA-2010-0005: VMware products address vulnerabilities in WebAccess
a. WebAccess Context Data Cross-site Scripting Vulnerability A cross-site scripting vulnerability in WebAccess allows for disclosure of sensitive information. The flaw is due to insufficient verification of certain parameters which may lead to redirection of a user's requests. This vulnerability can only be exploited if the attacker tricks the WebAccess user into clicking a malicious link and the attacker has control of a server on the same network as the system where WebAccess is being used.
CVEs: CVE-2009-2277, CVE-2010-0686, CVE-2010-1137, CVE-2010-1193
Affected products: ESXi, VMware Workstation
GHSA
GHSA-398r-4xmm-8gch: WebAccess in VMware VirtualCenter 2
ghsa_unreviewed·2022-05-02
CVE-2010-0686 [HIGH] CWE-20 GHSA-398r-4xmm-8gch: WebAccess in VMware VirtualCenter 2
WebAccess in VMware VirtualCenter 2.0.2 and 2.5, VMware Server 2.0, and VMware ESX 3.0.3 and 3.5 allows remote attackers to leverage proxy-server functionality to spoof the origin of requests via unspecified vectors, related to a "URL forwarding vulnerability."
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
http://lists.vmware.com/pipermail/security-announce/2010/000086.htmlhttp://www.securityfocus.com/bid/39037http://www.securitytracker.com/id?1023769http://www.vmware.com/security/advisories/VMSA-2010-0005.htmlhttp://lists.vmware.com/pipermail/security-announce/2010/000086.htmlhttp://www.securityfocus.com/bid/39037http://www.securitytracker.com/id?1023769http://www.vmware.com/security/advisories/VMSA-2010-0005.html
2010-04-01
Published