CVE-2010-1193
published 2010-04-01CVE-2010-1193: Cross-site scripting (XSS) vulnerability in WebAccess in VMware Server 2.0 allows remote attackers to inject arbitrary web script or HTML via vectors related…
PriorityP417medium4.3CVSS 2.0
AVNACMAuNCNIPAN
EPSS
1.66%
73.8th percentile
Cross-site scripting (XSS) vulnerability in WebAccess in VMware Server 2.0 allows remote attackers to inject arbitrary web script or HTML via vectors related to JSON error messages.
Affected
3 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| vmware | esxi | — | — |
| vmware | server | — | — |
| vmware | vmware_workstation | — | — |
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
VMware
VMware products address vulnerabilities in WebAccess
vendor_vmware·2010-03-29·CVSS 4.3
CVE-2009-2277 [MEDIUM] VMware products address vulnerabilities in WebAccess
VMSA-2010-0005: VMware products address vulnerabilities in WebAccess
a. WebAccess Context Data Cross-site Scripting Vulnerability A cross-site scripting vulnerability in WebAccess allows for disclosure of sensitive information. The flaw is due to insufficient verification of certain parameters which may lead to redirection of a user's requests. This vulnerability can only be exploited if the attacker tricks the WebAccess user into clicking a malicious link and the attacker has control of a server on the same network as the system where WebAccess is being used.
CVEs: CVE-2009-2277, CVE-2010-0686, CVE-2010-1137, CVE-2010-1193
Affected products: ESXi, VMware Workstation
GHSA
GHSA-f58m-4rgp-w5c6: Cross-site scripting (XSS) vulnerability in WebAccess in VMware Server 2
ghsa_unreviewed·2022-05-02
CVE-2010-1193 [MEDIUM] CWE-79 GHSA-f58m-4rgp-w5c6: Cross-site scripting (XSS) vulnerability in WebAccess in VMware Server 2
Cross-site scripting (XSS) vulnerability in WebAccess in VMware Server 2.0 allows remote attackers to inject arbitrary web script or HTML via vectors related to JSON error messages.
No detection rules found.
Exploit-DB
AOL Instant Messenger 4.0/4.1.2010/4.2.1193 - BuddyIcon Buffer Overflow
exploitdb·2000-12-12
CVE-2000-1094 AOL Instant Messenger 4.0/4.1.2010/4.2.1193 - BuddyIcon Buffer Overflow
AOL Instant Messenger 4.0/4.1.2010/4.2.1193 - BuddyIcon Buffer Overflow
---
source: https://www.securityfocus.com/bid/2122/info
AOL Instant Messenger (AIM) is a real time messaging service for users that are on line. When AOL Instant Messenger is installed, by default it configures the system so that the aim: URL protocol connects aim:// urls to the AIM client. There exists a buffer overflow in parsing aim:// URL parameters.
The buffer overflow has to do with the parsing of parameters associated with the "buddyicon" option. The stack overflow will occur If the "Source" parameter, which arguments the buddyicon option, is more than 3000 characters in length. It may be possible to execute arbitrary code. Since this vulnerability manifests itself in an URL, a user needs only to click on th
Exploit-DB
AOL Instant Messenger 3.5.1856/4.0/4.1.2010/4.2.1193 - 'aim://' Remote Buffer Overflow
exploitdb·2000-12-12
CVE-2000-1093 AOL Instant Messenger 3.5.1856/4.0/4.1.2010/4.2.1193 - 'aim://' Remote Buffer Overflow
AOL Instant Messenger 3.5.1856/4.0/4.1.2010/4.2.1193 - 'aim://' Remote Buffer Overflow
---
source: https://www.securityfocus.com/bid/2118/info
AOL Instant Messenger (AIM) is a real time messaging service for users that are on line. When AOL Instant Messenger is installed, by default it configures the system so that the aim: URL protocol connects aim:// urls to the AIM client. There exists a buffer overflow in parsing aim:// URL parameters.
This vulnerability exists in versions of AOL Instant previous to Messenger 4.3.2229. By sending a specially crafted URL ,using the 'aim:' protocol, comprised of 'goim' and 'screenname' parameters, it is possible for a remote user to overflow the buffer during a memory copy operation and execute arbitarary code.
It should be noted that the victim nee
No writeups or analysis indexed.
http://lists.vmware.com/pipermail/security-announce/2010/000086.htmlhttp://www.securityfocus.com/bid/39037http://www.securitytracker.com/id?1023769http://www.vmware.com/security/advisories/VMSA-2010-0005.htmlhttp://lists.vmware.com/pipermail/security-announce/2010/000086.htmlhttp://www.securityfocus.com/bid/39037http://www.securitytracker.com/id?1023769http://www.vmware.com/security/advisories/VMSA-2010-0005.html
2010-04-01
Published