CVE-2016-2078
published 2016-06-08CVE-2016-2078: Cross-site scripting (XSS) vulnerability in the Web Client in VMware vCenter Server 5.1 before update 3d, 5.5 before update 3d, and 6.0 before update 2 on…
PriorityP424medium6.1CVSS 3.0
AVNACLPRNUIRSCCLILAN
EPSS
1.07%
61.1th percentile
Cross-site scripting (XSS) vulnerability in the Web Client in VMware vCenter Server 5.1 before update 3d, 5.5 before update 3d, and 6.0 before update 2 on Windows allows remote attackers to inject arbitrary web script or HTML via the flashvars parameter.
Affected
6 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| vmware | vcenter_server | — | — |
| vmware | vcenter_server | — | — |
| vmware | vcenter_server | — | — |
| vmware | vcenter_server | — | — |
| vmware | vmware_vcenter_server | — | — |
| vmware | vsphere | — | — |
CVSS provenance
nvdv3.06.1MEDIUMCVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
nvdv2.04.3MEDIUMAV:N/AC:M/Au:N/C:N/I:P/A:N
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
VMware
VMware vCenter Server updates address an important cross-site scripting issue
vendor_vmware·2016-05-24·CVSS 6.1
CVE-2016-2078 [MEDIUM] VMware vCenter Server updates address an important cross-site scripting issue
VMSA-2016-0006: VMware vCenter Server updates address an important cross-site scripting issue
a. Reflected cross-site scripting issue through flash parameter injection The vSphere Web Client contains a reflected cross-site scripting vulnerability that occurs through flash parameter injection. An attacker can exploit this issue by tricking a victim into clicking a malicious link. VMware would like to thank John Page aka hyp3rlinx for reporting this issue to us. The Common Vulnerabilities and Exposures project (cve.mitre.org) has assigned the identifier CVE-2016-2078 to this issue. Column 4 of the following table lists the action required to remediate the vulnerability in each release, if a solution is available. VMware Product Product Version Running on Replace with/ Apply Patch VMware Pro
GHSA
GHSA-q464-c6w6-9rm7: Cross-site scripting (XSS) vulnerability in the Web Client in VMware vCenter Server 5
ghsa_unreviewed·2022-05-14
CVE-2016-2078 [MEDIUM] CWE-79 GHSA-q464-c6w6-9rm7: Cross-site scripting (XSS) vulnerability in the Web Client in VMware vCenter Server 5
Cross-site scripting (XSS) vulnerability in the Web Client in VMware vCenter Server 5.1 before update 3d, 5.5 before update 3d, and 6.0 before update 2 on Windows allows remote attackers to inject arbitrary web script or HTML via the flashvars parameter.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
http://hyp3rlinx.altervista.org/advisories/VMWARE-VSPHERE-FLASH-XSS.txthttp://packetstormsecurity.com/files/137189/VMWare-vSphere-Web-Client-6.0-Cross-Site-Scripting.htmlhttp://www.securityfocus.com/archive/1/538484/100/0/threadedhttp://www.securitytracker.com/id/1035961http://www.vmware.com/security/advisories/VMSA-2016-0006.htmlhttp://hyp3rlinx.altervista.org/advisories/VMWARE-VSPHERE-FLASH-XSS.txthttp://packetstormsecurity.com/files/137189/VMWare-vSphere-Web-Client-6.0-Cross-Site-Scripting.htmlhttp://www.securityfocus.com/archive/1/538484/100/0/threadedhttp://www.securitytracker.com/id/1035961http://www.vmware.com/security/advisories/VMSA-2016-0006.html
2016-06-08
Published