CVE Vulnerabilities

CVE-2005-3618

Published: Dec 31, 2005 | Modified: Oct 30, 2018
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
7.6 HIGH
AV:N/AC:H/Au:N/C:C/I:C/A:C
RedHat/V2
RedHat/V3
Ubuntu

Cross-site request forgery (CSRF) vulnerability in the management interface for VMware ESX Server 2.0.x before 2.0.2 patch 1, 2.1.x before 2.1.3 patch 1, and 2.x before 2.5.3 patch 2 allows allows remote attackers to perform unauthorized actions as the administrator via URLs, as demonstrated using the setUsr operation to change a password. NOTE: this issue can be leveraged with CVE-2005-3619 to automatically perform the attacks.

Affected Software

Name Vendor Start Version End Version
Esx Vmware 2.0.1 (including) 2.0.2 (excluding)
Esx Vmware 2.1.1 (including) 2.1.3 (excluding)
Esx Vmware 2.5.2 (including) 2.5.3 (excluding)

References