| |||||||||||||
| Test ID: | 1.3.6.1.4.1.25623.1.0.900899 |
| Category: | Denial of Service |
| Title: | VMware Server Multiple Cross-Site Scripting Vulnerabilities (Linux) |
| Summary: | Check for the version of VMware Server |
| Description: | Overview: The host is installed with VMWare Server that is vulnerable to multiple Cross-Site Scripting vulnerabilities. Vulnerability Insight: - Multiple vulnerabilities can be exploited to disclose sensitive information, conduct cross-site scripting attacks, manipulate certain data, bypass certain security restrictions, cause a DoS, or compromise a user's system. - Certain unspecified input passed to WebWorks help pages is not properly sanitised before being returned to the user. This can be exploited to execute arbitrary HTML and script code in a user's browser session in context of an affected site. Impact: Successful exploitation will lets attackers to cause a Denial of Service, or compromise a user's system. Impact Level: System/Application Affected Software/OS: VMware Server version 2.0.2 on Linux. Fix: Apply patch, http://kb.vmware.com/kb/1016594 ***** NOTE: Ignore this warning, if above mentioned patch is manually applied. ***** References: http://secunia.com/advisories/37460/ http://www.webworks.com/Security/2009-0001/ http://www.vmware.com/security/advisories/VMSA-2009-0017.html |
| Cross-Ref: |
BugTraq ID: 37346 Common Vulnerability Exposure (CVE) ID: CVE-2009-3731 Bugtraq: 20091215 VMSA-2009-0017 VMware vCenter, ESX patch and vCenter Lab Manager releases address cross-site scripting issues (Google Search) http://archives.neohapsis.com/archives/bugtraq/2009-12/0229.html Bugtraq: 20100304 CA20100304-01: Security Notice for CA SiteMinder (Google Search) http://www.securityfocus.com/archive/1/archive/1/509883/100/0/threaded http://lists.vmware.com/pipermail/security-announce/2009/000073.html http://www.securityfocus.com/bid/37346 http://www.osvdb.org/62738 http://www.osvdb.org/62739 http://www.osvdb.org/62740 http://www.osvdb.org/62741 http://www.osvdb.org/62742 http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:5944 http://securitytracker.com/id?1023683 http://secunia.com/advisories/38749 http://secunia.com/advisories/38842 |
| Copyright | Copyright (C) 2009 SecPod |
| This is only one of 32582 vulnerability tests in our test suite. Find out more about running a complete security audit. To run a free test of this vulnerability against your system, register below. |
|