CVE-2006-2481
CVE-2006-2481
VMware ESX Server 2.0.x before 2.0.2 and 2.x before 2.5.2 patch 4 stores authentication credentials in base 64 encoded format in the vmware.mui.kid and vmware.mui.sid cookies, which allows attackers to gain privileges by obtaining the cookies using attacks such as cross-site scripting (CVE-2005-3619).
Affected products
n/a · n/apublic PoCs found — 1
exploitdbwww.exploit-db.com/exploits/28312unverified⚠ Public resources, to assess the exposure of systems you control or are authorized to test. Test only with authorization.
Want to know if your infrastructure is exposed to this?
Talk to TrueHacking →References
http://kb.vmware.com/kb/2118366http://secunia.com/advisories/21230http://www.corsaire.com/advisories/c060512-001.txthttp://www.securityfocus.com/archive/1/441728/100/100/threadedhttp://www.securityfocus.com/archive/1/441825/100/100/threadedhttp://www.securityfocus.com/bid/19249http://www.vupen.com/english/advisories/2006/3075