Cross-Site Scripting Vulnerability in Dell iDRAC6 and iDRAC7 Products
CVE-2013-3589

Currently unrated

Key Information:

Vendor
Dell
Vendor
CVE Published:
24 September 2013

Summary

A Cross-site scripting (XSS) vulnerability exists in the login page of the Administrative Web Interface for Dell iDRAC6 and iDRAC7 devices. This flaw allows remote attackers to inject arbitrary web scripts or HTML by manipulating the ErrorMsg parameter. Devices running firmware prior to version 1.96 for iDRAC6 and 1.46.45 for iDRAC7 are impacted, potentially exposing sensitive information and compromising security.

References

Timeline

  • Vulnerability Reserved

  • Vulnerability published

.