Cross-Site Scripting Vulnerability in Dell iDRAC6 and iDRAC7 Products
CVE-2013-3589
Currently unrated
Summary
A Cross-site scripting (XSS) vulnerability exists in the login page of the Administrative Web Interface for Dell iDRAC6 and iDRAC7 devices. This flaw allows remote attackers to inject arbitrary web scripts or HTML by manipulating the ErrorMsg parameter. Devices running firmware prior to version 1.96 for iDRAC6 and 1.46.45 for iDRAC7 are impacted, potentially exposing sensitive information and compromising security.
References
Timeline
Vulnerability Reserved
Vulnerability published