CVE-2009-2277: XSS
Cross-site scripting (XSS) vulnerability in WebAccess in VMware VirtualCenter 2.0.2 and 2.5 and VMware ESX 3.0.3 and 3.5 allows remote attackers to inject arbitrary web script or HTML via vectors related to "context data."
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2009-2277?
CVE-2009-2277 is classified as a medium severity vulnerability due to potential cross-site scripting (XSS) risks.
How do I fix CVE-2009-2277?
To address CVE-2009-2277, you should upgrade to a patched version of VMware VirtualCenter or VMware ESX.
Who is affected by CVE-2009-2277?
CVE-2009-2277 affects users of VMware VirtualCenter versions 2.0.2 and 2.5, as well as VMware ESX versions 3.0.3 and 3.5.
What impact does CVE-2009-2277 have?
CVE-2009-2277 allows remote attackers to execute arbitrary web scripts or HTML on affected systems.
Is CVE-2009-2277 easy to exploit?
CVE-2009-2277 has an easy exploitation vector due to its reliance on user input in web contexts.