CVE-2013-3589
4.3
Vector
AV:N/AC:M/Au:N/C:N/I:P/A:N
Exploitability: 8.6 / Impact: 2.9
Source: NVD
Description
Cross-site scripting (XSS) vulnerability in the login page in the Administrative Web Interface on Dell iDRAC6 monolithic devices with firmware before 1.96 and iDRAC7 devices with firmware before 1.46.45 allows remote attackers to inject arbitrary web script or HTML via the ErrorMsg parameter.
Affected (17)
Products: Dell: Idrac6 Firmware, Idrac6 Monolithic, Idrac7 Firmware, Idrac7
Configuration A
| Vulnerable Software | Affected Versions |
|---|---|
| Up to 1.95 | |
| All versions |
Configuration B
| Vulnerable Software | Affected Versions |
|---|---|
| Up to 1.40.40 | |
| All versions |
References (4)
Source: af854a3a-2127-422b-91ae-364da2661108
US Government Resource
Source: af854a3a-2127-422b-91ae-364da2661108
US Government Resource
Timeline
No history available yet.