Back

CVE-2005-3619

Cross-site scripting (XSS) vulnerability in the management interface for VMware ESX 2.5.x before 2.5.2 upgrade patch 2, 2.1.x before 2.1.2 upgrade patch 6, and 2.0.x before 2.0.1 upgrade patch 6 allows remote attackers to inject arbitrary web script or HTML via messages that are not sanitized when viewing syslog log files.

Published: Dec 31, 2005 Modified: Jun 16, 2026

CVSS Metrics

Affected Products (6)

Vendor Product Version
vmware esx 2.0
vmware esx 2.0.1
vmware esx 2.1.1
vmware esx 2.1.2
vmware esx 2.5
vmware esx 2.5.2

GitHub Security Advisory GHSA-jppx-j8c9-3cxq

Cross-site scripting (XSS) vulnerability in the management interface for VMware ESX 2.5.x before...

Risk Scores

CVSS Score 6.8 / 10
EPSS Score 1.42%

Top 29% most likely to be exploited

Threat Score 27.6 / 100

Data Sources

NVD EPSS GitHub