Anfälligkeitssuche        Suche in 324607 CVE Beschreibungen
und 145615 Test Beschreibungen,
Zugriff auf 10,000+ Quellverweise.
Tests   CVE   Alle  

Test Kennung:1.3.6.1.4.1.25623.1.0.900896
Kategorie:Denial of Service
Titel:VMware Server Multiple XSS Vulnerabilities - Windows
Zusammenfassung:VMWare Server is prone to multiple cross-site scripting (XSS); vulnerabilities.
Beschreibung:Summary:
VMWare Server is prone to multiple cross-site scripting (XSS)
vulnerabilities.

Vulnerability Insight:
- Multiple vulnerabilities can be exploited to disclose sensitive information,
conduct cross-site scripting attacks, manipulate certain data, bypass certain
security restrictions, cause a DoS, or compromise a user's system.

- Certain unspecified input passed to WebWorks help pages is not properly
sanitised before being returned to the user. This can be exploited to execute
arbitrary HTML and script code in a user's browser session in the context of an affected site.

Vulnerability Impact:
Successful exploitation will lets attackers to cause a Denial of Service, or
compromise a user's system.

Affected Software/OS:
VMware Server version 2.0.2 on Windows.

Solution:
Apply the patch from the referenced advisory.

CVSS Score:
4.3

CVSS Vector:
AV:N/AC:M/Au:N/C:N/I:P/A:N

Querverweis: Common Vulnerability Exposure (CVE) ID: CVE-2009-3731
BugTraq ID: 37346
http://www.securityfocus.com/bid/37346
Bugtraq: 20091215 VMSA-2009-0017 VMware vCenter, ESX patch and vCenter Lab Manager releases address cross-site scripting issues (Google Search)
http://archives.neohapsis.com/archives/bugtraq/2009-12/0229.html
Bugtraq: 20100304 CA20100304-01: Security Notice for CA SiteMinder (Google Search)
http://www.securityfocus.com/archive/1/509883/100/0/threaded
http://lists.vmware.com/pipermail/security-announce/2009/000073.html
http://www.osvdb.org/62738
http://www.osvdb.org/62739
http://www.osvdb.org/62740
http://www.osvdb.org/62741
http://www.osvdb.org/62742
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A5944
http://securitytracker.com/id?1023683
http://secunia.com/advisories/38749
http://secunia.com/advisories/38842
CopyrightCopyright (C) 2009 Greenbone AG

Dies ist nur einer von 145615 Anfälligkeitstests in unserem Testpaket. Finden Sie mehr über unsere vollständigen Sicherheitsüberprüfungen heraus.

Um einen gratis Test für diese Anfälligkeit auf Ihrem System durchlaufen zu lassen, registrieren Sie sich bitte unten.




© 1998-2025 E-Soft Inc. Alle Rechte vorbehalten.