{"api_version":"1","generated_at":"2026-07-23T07:34:23+00:00","cve":"CVE-2017-15092","urls":{"html":"https://cve.report/CVE-2017-15092","api":"https://cve.report/api/cve/CVE-2017-15092.json","docs":"https://cve.report/api","cve_org":"https://www.cve.org/CVERecord?id=CVE-2017-15092","nvd":"https://nvd.nist.gov/vuln/detail/CVE-2017-15092"},"summary":{"title":"CVE-2017-15092","description":"A cross-site scripting issue has been found in the web interface of PowerDNS Recursor from 4.0.0 up to and including 4.0.6, where the qname of DNS queries was displayed without any escaping, allowing a remote attacker to inject HTML and Javascript code into the web interface, altering the content.","state":"PUBLIC","assigner":"secalert@redhat.com","published_at":"2018-01-23 15:29:00","updated_at":"2019-10-09 23:24:00"},"problem_types":["CWE-79"],"metrics":[],"references":[{"url":"https://doc.powerdns.com/recursor/security-advisories/powerdns-advisory-2017-05.html","name":"https://doc.powerdns.com/recursor/security-advisories/powerdns-advisory-2017-05.html","refsource":"CONFIRM","tags":["Patch","Vendor Advisory"],"title":"PowerDNS Security Advisory 2017-05: Cross-Site Scripting in the web interface — PowerDNS Recursor  documentation","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://www.securityfocus.com/bid/101982","name":"101982","refsource":"BID","tags":["Third Party Advisory","VDB Entry"],"title":"","mime":"text/html","httpstatus":"200","archivestatus":"0"},{"url":"https://www.cve.org/CVERecord?id=CVE-2017-15092","name":"CVE Program record","refsource":"CVE.ORG","tags":["canonical"]},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2017-15092","name":"NVD vulnerability detail","refsource":"NVD","tags":["canonical","analysis"]}],"affected":[],"timeline":[],"solutions":[],"workarounds":[],"exploits":[],"credits":[],"nvd_cpes":[{"cve_year":"2017","cve_id":"15092","vulnerable":"1","versionEndIncluding":"4.0.6","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"powerdns","cpe5":"recursor","cpe6":"*","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"}],"vendor_comments":[],"enrichments":{"kev":null,"epss":null,"legacy_qids":[{"cve":"CVE-2017-15092","qid":"501110","title":"Alpine Linux Security Update for pdns-recursor"}]},"source_records":{"cve_program":{"CVE_data_meta":{"ASSIGNER":"secalert@redhat.com","DATE_PUBLIC":"2017-11-27T00:00:00","ID":"CVE-2017-15092","STATE":"PUBLIC"},"affects":{"vendor":{"vendor_data":[{"product":{"product_data":[{"product_name":"PowerDNS Recursor","version":{"version_data":[{"version_value":"from 4.0.0 up to and including 4.0.6"}]}}]},"vendor_name":"PowerDNS"}]}},"data_format":"MITRE","data_type":"CVE","data_version":"4.0","description":{"description_data":[{"lang":"eng","value":"A cross-site scripting issue has been found in the web interface of PowerDNS Recursor from 4.0.0 up to and including 4.0.6, where the qname of DNS queries was displayed without any escaping, allowing a remote attacker to inject HTML and Javascript code into the web interface, altering the content."}]},"problemtype":{"problemtype_data":[{"description":[{"lang":"eng","value":"CWE-79"}]}]},"references":{"reference_data":[{"name":"101982","refsource":"BID","url":"http://www.securityfocus.com/bid/101982"},{"name":"https://doc.powerdns.com/recursor/security-advisories/powerdns-advisory-2017-05.html","refsource":"CONFIRM","url":"https://doc.powerdns.com/recursor/security-advisories/powerdns-advisory-2017-05.html"}]}},"nvd":{"publishedDate":"2018-01-23 15:29:00","lastModifiedDate":"2019-10-09 23:24:00","problem_types":["CWE-79"],"metrics":{"baseMetricV3":{"cvssV3":{"version":"3.0","vectorString":"CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"REQUIRED","scope":"CHANGED","confidentialityImpact":"LOW","integrityImpact":"LOW","availabilityImpact":"NONE","baseScore":6.1,"baseSeverity":"MEDIUM"},"exploitabilityScore":2.8,"impactScore":2.7},"baseMetricV2":{"cvssV2":{"version":"2.0","vectorString":"AV:N/AC:M/Au:N/C:N/I:P/A:N","accessVector":"NETWORK","accessComplexity":"MEDIUM","authentication":"NONE","confidentialityImpact":"NONE","integrityImpact":"PARTIAL","availabilityImpact":"NONE","baseScore":4.3},"severity":"MEDIUM","exploitabilityScore":8.6,"impactScore":2.9,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":true}},"configurations":{"CVE_data_version":"4.0","nodes":[{"operator":"OR","children":[],"cpe_match":[{"vulnerable":true,"cpe23Uri":"cpe:2.3:a:powerdns:recursor:*:*:*:*:*:*:*:*","versionStartIncluding":"4.0.0","versionEndIncluding":"4.0.6","cpe_name":[]}]}]}},"legacy_mitre":{"record":{"CveYear":"2017","CveId":"15092","Ordinal":"112594","Title":"CVE-2017-15092","CVE":"CVE-2017-15092","Year":"2017"},"notes":[{"CveYear":"2017","CveId":"15092","Ordinal":"1","NoteData":"A cross-site scripting issue has been found in the web interface of PowerDNS Recursor from 4.0.0 up to and including 4.0.6, where the qname of DNS queries was displayed without any escaping, allowing a remote attacker to inject HTML and Javascript code into the web interface, altering the content.","Type":"Description","Title":null},{"CveYear":"2017","CveId":"15092","Ordinal":"2","NoteData":"2018-01-23","Type":"Other","Title":"Published"},{"CveYear":"2017","CveId":"15092","Ordinal":"3","NoteData":"2018-01-24","Type":"Other","Title":"Modified"}]}}}