![]() |
Startseite ▼ Bookkeeping
Online ▼ Sicherheits
Überprüfungs ▼
Verwaltetes
DNS ▼
Info
Bestellen/Erneuern
FAQ
AUP
Dynamic DNS Clients
Domaine konfigurieren Dyanmic DNS Update Password Netzwerk
Überwachung ▼
Enterprise
Erweiterte
Standard
Gratis Test
FAQ
Preis/Funktionszusammenfassung
Bestellen
Beispiele
Konfigurieren/Status Alarm Profile | ||
Test Kennung: | 1.3.6.1.4.1.25623.1.0.900896 |
Kategorie: | Denial of Service |
Titel: | VMware Server Multiple XSS Vulnerabilities - Windows |
Zusammenfassung: | VMWare Server is prone to multiple cross-site scripting (XSS); vulnerabilities. |
Beschreibung: | Summary: VMWare Server is prone to multiple cross-site scripting (XSS) vulnerabilities. Vulnerability Insight: - Multiple vulnerabilities can be exploited to disclose sensitive information, conduct cross-site scripting attacks, manipulate certain data, bypass certain security restrictions, cause a DoS, or compromise a user's system. - Certain unspecified input passed to WebWorks help pages is not properly sanitised before being returned to the user. This can be exploited to execute arbitrary HTML and script code in a user's browser session in the context of an affected site. Vulnerability Impact: Successful exploitation will lets attackers to cause a Denial of Service, or compromise a user's system. Affected Software/OS: VMware Server version 2.0.2 on Windows. Solution: Apply the patch from the referenced advisory. CVSS Score: 4.3 CVSS Vector: AV:N/AC:M/Au:N/C:N/I:P/A:N |
Querverweis: |
Common Vulnerability Exposure (CVE) ID: CVE-2009-3731 BugTraq ID: 37346 http://www.securityfocus.com/bid/37346 Bugtraq: 20091215 VMSA-2009-0017 VMware vCenter, ESX patch and vCenter Lab Manager releases address cross-site scripting issues (Google Search) http://archives.neohapsis.com/archives/bugtraq/2009-12/0229.html Bugtraq: 20100304 CA20100304-01: Security Notice for CA SiteMinder (Google Search) http://www.securityfocus.com/archive/1/509883/100/0/threaded http://lists.vmware.com/pipermail/security-announce/2009/000073.html http://www.osvdb.org/62738 http://www.osvdb.org/62739 http://www.osvdb.org/62740 http://www.osvdb.org/62741 http://www.osvdb.org/62742 https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A5944 http://securitytracker.com/id?1023683 http://secunia.com/advisories/38749 http://secunia.com/advisories/38842 |
Copyright | Copyright (C) 2009 Greenbone AG |
Dies ist nur einer von 145615 Anfälligkeitstests in unserem Testpaket. Finden Sie mehr über unsere vollständigen Sicherheitsüberprüfungen heraus. Um einen gratis Test für diese Anfälligkeit auf Ihrem System durchlaufen zu lassen, registrieren Sie sich bitte unten. |