CVE-2009-2277
VMware VirtualCenter <2.5 - VMware ESX <3.5 - XSS
Title source: llmDescription
Cross-site scripting (XSS) vulnerability in WebAccess in VMware VirtualCenter 2.0.2 and 2.5 and VMware ESX 3.0.3 and 3.5 allows remote attackers to inject arbitrary web script or HTML via vectors related to "context data."
References (4)
Scores
EPSS
0.0037
EPSS Percentile
58.2%
Classification
CWE
CWE-79
Status
published
Affected Products (5)
vmware/esx_server
vmware/esx_server
vmware/virtualcenter
vmware/virtualcenter
n/a/n/a
Timeline
Published
Apr 01, 2010
Tracked Since
Feb 18, 2026