CVE-2017-15092
Last modified
CVE-2017-15092 is a vulnerability of currently unknown severity. A cross-site scripting issue has been found in the web interface of PowerDNS Recursor from 4.0.0 up to and including 4.0.6, where the qname of DNS queries was displayed without any escaping, allowing a remote attacker to inject HTML and Javascript code into the web interface, altering the content.. EPSS estimates a 2.32% chance of exploitation in the next 30 days.
Description
A cross-site scripting issue has been found in the web interface of PowerDNS Recursor from 4.0.0 up to and including 4.0.6, where the qname of DNS queries was displayed without any escaping, allowing a remote attacker to inject HTML and Javascript code into the web interface, altering the content.
Metrics
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Powerdns | Recursor | >= 4.0.0, <= 4.0.6 |
References
- http://www.securityfocus.com/bid/101982Third Party Advisory, VDB Entry
- https://doc.powerdns.com/recursor/security-advisories/powerdns-advisory-2017-05.htmlPatch, Vendor Advisory
- http://www.securityfocus.com/bid/101982Third Party Advisory, VDB Entry
- https://doc.powerdns.com/recursor/security-advisories/powerdns-advisory-2017-05.htmlPatch, Vendor Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2017-15092?
How severe is CVE-2017-15092?
How do I fix CVE-2017-15092?
Are you affected by CVE-2017-15092?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
