Vulnerabilities > CVE-2006-2481 - Credentials Management vulnerability in VMWare ESX

047910
CVSS 5.0 - MEDIUM
Attack vector
NETWORK
Attack complexity
LOW
Privileges required
NONE
Confidentiality impact
PARTIAL
Integrity impact
NONE
Availability impact
NONE
network
low complexity
vmware
CWE-255
exploit available

Summary

VMware ESX Server 2.0.x before 2.0.2 and 2.x before 2.5.2 patch 4 stores authentication credentials in base 64 encoded format in the vmware.mui.kid and vmware.mui.sid cookies, which allows attackers to gain privileges by obtaining the cookies using attacks such as cross-site scripting (CVE-2005-3619).

Common Weakness Enumeration (CWE)

Exploit-Db

descriptionVMware ESX 2.x Multiple Information Disclosure Vulnerabilities. CVE-2006-2481. Remote exploits for multiple platform
idEDB-ID:28312
last seen2016-02-03
modified2006-07-31
published2006-07-31
reporterStephen de Vries
sourcehttps://www.exploit-db.com/download/28312/
titleVMware ESX 2.x - Multiple Information Disclosure Vulnerabilities