Dell OpenManage Server Administrator 'HelpViewer' Redirect

medium Nessus Plugin ID 46738

Synopsis

The remote web server hosts an application with an open redirect.

Description

Dell OpenManage Server Administrator appears to be installed on the remote host. The installed version fails to validate input passed to the 'file' parameter in '/servlet/HelpViewer' before redirecting an unauthenticated user to the location it specifies.

An attacker may be able to exploit this issue to conduct phishing attacks by tricking users into visiting malicious websites.

Solution

Unknown at this time.

Plugin Details

Severity: Medium

ID: 46738

File Name: dell_openmanage_helpviewer_redirect.nasl

Version: 1.12

Type: remote

Family: CGI abuses

Published: 5/26/2010

Updated: 1/19/2021

Supported Sensors: Nessus

Risk Information

CVSS Score Rationale: No cve available for this vulnerability.

CVSS v2

Risk Factor: Medium

Base Score: 4.3

Temporal Score: 3.6

Vector: CVSS2#AV:N/AC:M/Au:N/C:N/I:P/A:N

CVSS Score Source: manual

CVSS v3

Risk Factor: Medium

Base Score: 4.7

Temporal Score: 4.4

Vector: CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:N/I:L/A:N

Temporal Vector: CVSS:3.0/E:F/RL:O/RC:X

Vulnerability Information

CPE: cpe:/a:dell:openmanage

Required KB Items: www/dell_omsa

Excluded KB Items: Settings/disable_cgi_scanning

Exploit Available: true

Exploit Ease: Exploits are available

Exploited by Nessus: true

Vulnerability Publication Date: 5/19/2010

Reference Information

BID: 40247

Secunia: 39879