6.1
CVSSv3

CVE-2016-2078

Published: 08/06/2016 Updated: 09/10/2018
CVSS v2 Base Score: 4.3 | Impact Score: 2.9 | Exploitability Score: 8.6
CVSS v3 Base Score: 6.1 | Impact Score: 2.7 | Exploitability Score: 2.8
VMScore: 383
Vector: AV:N/AC:M/Au:N/C:N/I:P/A:N

Vulnerability Summary

Cross-site scripting (XSS) vulnerability in the Web Client in VMware vCenter Server 5.1 before update 3d, 5.5 before update 3d, and 6.0 before update 2 on Windows allows remote malicious users to inject arbitrary web script or HTML via the flashvars parameter.

Vulnerable Product Search on Vulmon Subscribe to Product

vmware vcenter server 5.1

vmware vcenter server 5.5

vmware vcenter server 6.0

vmware vcenter server 5.0

Exploits

VMWare vSphere web client versions 51 through 60 suffer from a flash cross site scripting vulnerability ...