CVE Vulnerabilities

CVE-2006-2481

Published: Jul 31, 2006 | Modified: Oct 30, 2018
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
5 MEDIUM
AV:N/AC:L/Au:N/C:P/I:N/A:N
RedHat/V2
RedHat/V3
Ubuntu

VMware ESX Server 2.0.x before 2.0.2 and 2.x before 2.5.2 patch 4 stores authentication credentials in base 64 encoded format in the vmware.mui.kid and vmware.mui.sid cookies, which allows attackers to gain privileges by obtaining the cookies using attacks such as cross-site scripting (CVE-2005-3619).

Affected Software

Name Vendor Start Version End Version
Esx Vmware 2.0 (including) 2.0 (including)
Esx Vmware 2.0.1 (including) 2.0.1 (including)
Esx Vmware 2.1 (including) 2.1 (including)
Esx Vmware 2.1.1 (including) 2.1.1 (including)
Esx Vmware 2.1.2 (including) 2.1.2 (including)
Esx Vmware 2.5 (including) 2.5 (including)
Esx Vmware 2.5.2 (including) 2.5.2 (including)

References