CVE-2017-15092
Summary
| CVE | CVE-2017-15092 |
|---|---|
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2018-01-23 15:29:00 UTC |
| Updated | 2019-10-09 23:24:00 UTC |
| Description | A cross-site scripting issue has been found in the web interface of PowerDNS Recursor from 4.0.0 up to and including 4.0.6, where the qname of DNS queries was displayed without any escaping, allowing a remote attacker to inject HTML and Javascript code into the web interface, altering the content. |
Risk And Classification
Problem Types: CWE-79
NVD Known Affected Configurations (CPE 2.3)
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| PowerDNS Security Advisory 2017-05: Cross-Site Scripting in the web interface — PowerDNS Recursor documentation | CONFIRM | doc.powerdns.com | Patch, Vendor Advisory |
| 101982 | BID | www.securityfocus.com | Third Party Advisory, VDB Entry |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
Legacy QID Mappings
- 501110 Alpine Linux Security Update for pdns-recursor