VMware VirtualCenter Directory Traversal Vulnerability
BID:32172
Info
VMware VirtualCenter Directory Traversal Vulnerability
| Bugtraq ID: | 32172 |
| Class: | Input Validation Error |
| CVE: |
CVE-2008-4281 |
| Remote: | Yes |
| Local: | No |
| Published: | Nov 06 2008 12:00AM |
| Updated: | Nov 10 2008 05:45PM |
| Credit: | Michel Toussaint |
| Vulnerable: |
VMWare ESXi Server 3.5 VMWare ESX Server 3.5 |
| Not Vulnerable: | |
Discussion
VMware VirtualCenter Directory Traversal Vulnerability
VMware VirtualCenter is prone to a directory-traversal vulnerability caused by an unspecified input-validation error.
Successful exploits may allow an administrator with limited privileges to gain elevated privileges.
This issue affects the following applications:
ESXi 3.5 prior to ESXe350-200810401-O-UG
ESX 3.5 prior to ESX350-200810201-UG
VMware VirtualCenter is prone to a directory-traversal vulnerability caused by an unspecified input-validation error.
Successful exploits may allow an administrator with limited privileges to gain elevated privileges.
This issue affects the following applications:
ESXi 3.5 prior to ESXe350-200810401-O-UG
ESX 3.5 prior to ESX350-200810201-UG
Exploit / POC
VMware VirtualCenter Directory Traversal Vulnerability
Attackers will likely use filesystem utilities or a browser to carry out this attack.
Attackers will likely use filesystem utilities or a browser to carry out this attack.
Solution / Fix
VMware VirtualCenter Directory Traversal Vulnerability
Solution:
The vendor has released an advisory and fixes. Please see the references for more information.
Solution:
The vendor has released an advisory and fixes. Please see the references for more information.
References
VMware VirtualCenter Directory Traversal Vulnerability
References:
References:
- VMware Homepage (VMware)
- VMSA-2008-0018 VMware Hosted products and patches for ESX and ESXi resolve two s (VMware Security Team
) - VMware Security Advisory VMSA-2008-0018 (VMware)