6.9
CVSSv2

CVE-2008-0923

Published: 26/02/2008 Updated: 15/10/2018
CVSS v2 Base Score: 6.9 | Impact Score: 10 | Exploitability Score: 3.4
VMScore: 614
Vector: AV:L/AC:M/Au:N/C:C/I:C/A:C

Vulnerability Summary

Directory traversal vulnerability in the Shared Folders feature for VMWare ACE 1.0.2 and 2.0.2, Player 1.0.4 and 2.0.2, and Workstation 5.5.4 and 6.0.2 allows guest OS users to read and write arbitrary files on the host OS via a multibyte string that produces a wide character string containing .. (dot dot) sequences, which bypasses the protection mechanism, as demonstrated using a "%c0%2e%c0%2e" string.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

vmware ace 2.0.1

vmware ace 2.0.2

vmware workstation 5.5.3_build_34685

vmware workstation 5.5.4

vmware player 1.0.4

vmware vmware player 1.0.1_build_19317

vmware workstation 6.0

vmware ace 1.0.2

vmware ace 2.0

vmware vmware workstation 6.0.2

vmware workstation 4.5.2

vmware ace 1.0

vmware vmware player 1.0.2

vmware vmware player 1.0.3

vmware vmware workstation 6.0.1

Exploits

Core Security Technologies Advisory - A vulnerability was found in VMware's shared folders mechanism that grants users of a Guest system read and write access to any portion of the Host's file system including the system folder and other security-sensitive files Exploitation of this vulnerability allows attackers to break out of an isolated Guest ...

Github Repositories

¿Qué es? Es una tecnología que permite encapsular aplicaciones y sus entornos en contenedores individuales Múltiples contenedores pueden correr en la misma máquina ya que cada uno de ellos se ejecuta en un entorno protegido de resto, lo que se conoce como sandbox Es la evolución lógica del alojamiento web, ya que se ha pasado d