Dell OpenManage Server Administrator /help/sm/en/Output/wwhelp/wwhimpl/js/html/index_main.htm Topic Parameter XSS Vulnerability
14 Mar. 2013
Summary
Dell openmanage serveradministrator/help/sm/en/Output/wwhelp/wwhimpl/js/html/index_main.htm is prone to a topic oparameter XSS vulnerability.
Credit:
The information has been provided by Tenable Network Security - Tenable Network Security.
The original article can be found at: http://www.dell.com/
Vulnerable Systems:
*OpenManage Server Administrator 6.5.0.1 and prior
Dell OpenManage Server Administrator contains a flaw that allows a remote cross-site scripting (XSS) attack. This flaw exists because the application does not validate the 'topic' parameter upon submission to the /help/sm/en/Output/wwhelp/wwhimpl/js/html/index_main.htm script. This may allow an attacker to create a specially crafted request that would execute arbitrary script code in a user's browser within the trust relationship between their browser and the server.