CVE-2009-2277

VMware VirtualCenter <2.5 - VMware ESX <3.5 - XSS

Title source: llm

Description

Cross-site scripting (XSS) vulnerability in WebAccess in VMware VirtualCenter 2.0.2 and 2.5 and VMware ESX 3.0.3 and 3.5 allows remote attackers to inject arbitrary web script or HTML via vectors related to "context data."

Scores

EPSS 0.0037
EPSS Percentile 58.2%

Classification

CWE
CWE-79
Status published

Affected Products (5)

vmware/esx_server
vmware/esx_server
vmware/virtualcenter
vmware/virtualcenter
n/a/n/a

Timeline

Published Apr 01, 2010
Tracked Since Feb 18, 2026