Files ≈ Packet Storm Packet Storm - Information Security News, Files, Tools, Exploits, Advisories and Whitepapers http://packetstormsecurity.org/ en-us Mon, 28 May 2012 04:51:35 GMT Packet Storm 144400 http://packetstormsecurity.org/ http://www.google-analytics.com/__utm.gif?utmwv=1.3&utmn=1249349492&utmcs=ISO-8859-1&utmsr=31337x31337&utmsc=32-bit&utmul=en-us&utmje=0&utmfl=-&utmcn=1&utmdt=Files%u2248%20Packet%20Storm&utmhn=packetstormsecurity.org&utmr=-&utmp=%2F1007-advisories%2FVMSA-2010-0012.txt%2F&utmac=UA-18885198-1&utmcc=__utma%3D32867617.1249349492.1338180695.1338180695.1338180695.1%3B%2B__utmz%3D32867617.1338180695.1.1.utmccn%3D(direct)%7Cutmcsr%3D(direct)%7Cutmcmd%3D(none) VMware Security Advisory 2010-0012 http://packetstormsecurity.org/files/91983/VMSA-2010-0012.txt http://packetstormsecurity.org/files/91983/VMSA-2010-0012.txt http://packetstormsecurity.org/files/91983/VMware-Security-Advisory-2010-0012.html Tue, 20 Jul 2010 01:20:44 GMT VMware Security Advisory - The default version of the Jetty Web server in Update Manager is version 6.1.6 for which the following relevant vulnerabilities are reported. A directory traversal vulnerability in Jetty allows for obtaining files from the system where Update Manager is installed by a remote, unauthenticated attacker. The attacker would need to be on the same network as the system where Update Manager is installed. A cross-site scripting vulnerability in Jetty allows for running JavaScript in the browser of the user who clicks a URL containing a malicious request to Update Manager. For an attack to be successful the attacker would need to lure the user into clicking the malicious URL.