Vulnerabilities > Vmware > Virtualcenter > 2.0.2

DATE CVE VULNERABILITY TITLE RISK
2010-04-01 CVE-2010-1137 Cross-Site Scripting vulnerability in VMWare ESX Server, Server and Virtualcenter
Cross-site scripting (XSS) vulnerability in WebAccess in VMware VirtualCenter 2.0.2 and 2.5 and VMware ESX 3.0.3 and 3.5, and the Server Console in VMware Server 1.0, allows remote attackers to inject arbitrary web script or HTML via the name of a virtual machine.
network
vmware CWE-79
4.3
2010-04-01 CVE-2010-0686 Improper Input Validation vulnerability in VMWare ESX Server, Server and Virtualcenter
WebAccess in VMware VirtualCenter 2.0.2 and 2.5, VMware Server 2.0, and VMware ESX 3.0.3 and 3.5 allows remote attackers to leverage proxy-server functionality to spoof the origin of requests via unspecified vectors, related to a "URL forwarding vulnerability."
network
low complexity
vmware CWE-20
7.5
2010-04-01 CVE-2009-2277 Cross-Site Scripting vulnerability in VMWare ESX Server and Virtualcenter
Cross-site scripting (XSS) vulnerability in WebAccess in VMware VirtualCenter 2.0.2 and 2.5 and VMware ESX 3.0.3 and 3.5 allows remote attackers to inject arbitrary web script or HTML via vectors related to "context data."
network
vmware CWE-79
4.3
2008-10-06 CVE-2008-4278 Information Exposure vulnerability in VMWare Virtualcenter
VMware VirtualCenter 2.5 before Update 3 build 119838 on Windows displays a user's password in cleartext when the password contains unspecified special characters, which allows physically proximate attackers to steal the password.
local
low complexity
vmware microsoft CWE-200
2.1
2008-08-13 CVE-2008-3514 Information Exposure vulnerability in VMWare Virtualcenter 2.0.2/2.5
VMware VirtualCenter 2.5 before Update 2 and 2.0.2 before Update 5 relies on client-side "enabled/disabled functionality" for access control, which allows remote attackers to determine valid user names by enabling functionality in the GUI and then making an "attempt to assign permissions to other system users." Patch information with appropriate login and password: http://www.vmware.com/security/advisories/VMSA-2008-0012.html 4.
network
low complexity
vmware CWE-200
5.0