Medium severity6.1NVD Advisory· Published Jun 8, 2016· Updated Jun 17, 2026
CVE-2016-2078
CVE-2016-2078
Description
Cross-site scripting (XSS) vulnerability in the Web Client in VMware vCenter Server 5.1 before update 3d, 5.5 before update 3d, and 6.0 before update 2 on Windows allows remote attackers to inject arbitrary web script or HTML via the flashvars parameter.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
5cpe:2.3:a:vmware:vcenter_server:5.0:*:*:*:*:*:*:*+ 4 more
- cpe:2.3:a:vmware:vcenter_server:5.0:*:*:*:*:*:*:*
- cpe:2.3:a:vmware:vcenter_server:5.1:*:*:*:*:*:*:*
- cpe:2.3:a:vmware:vcenter_server:5.5:*:*:*:*:*:*:*
- cpe:2.3:a:vmware:vcenter_server:6.0:*:*:*:*:*:*:*
- (no CPE)range: 5.1 before update 3d; 5.5 before update 3d; 6.0 before update 2
Patches
Vulnerability mechanics
References
5- packetstormsecurity.com/files/137189/VMWare-vSphere-Web-Client-6.0-Cross-Site-Scripting.htmlnvdExploit
- www.vmware.com/security/advisories/VMSA-2016-0006.htmlnvdVendor Advisory
- hyp3rlinx.altervista.org/advisories/VMWARE-VSPHERE-FLASH-XSS.txtnvd
- www.securityfocus.com/archive/1/538484/100/0/threadednvd
- www.securitytracker.com/id/1035961nvd
News mentions
0No linked articles in our index yet.