CVE-2017-15287
MEDIUMNuclei
Dreambox Plugin BouquetEditor - Cross-Site Scripting
Record summary
CVE-2017-15287 has a selected CVSS score of 6.1 (medium); EIP currently links 1 catalogued exploit and 1 Nuclei template.
Proofs of concept
1Catalogued exploits
ExploitDBDreambox Plugin BouquetEditor - Cross-Site ScriptingExploitDB exploitby Thiago SenaNot analyzed1 file
Nuclei templates
1ProjectDiscoveryMEDIUMDreambox WebControl 2.0.0 - Cross-Site ScriptingCVSS 6.1
Dream Multimedia Dreambox devices via their WebControl component are vulnerable to reflected cross-site scripting, as demonstrated by the "Name des Bouquets" field, or the file parameter to the /file URI.
Impact
Successful exploitation of this vulnerability could allow an attacker to execute arbitrary JavaScript code in the context of the victim's browser, leading to session hijacking, defacement, or theft of sensitive information.
Remediation
Upgrade to a patched version of Dreambox WebControl or apply appropriate input sanitization to prevent XSS attacks.
WeaknessesCWE-79
Authorspikpikcu
Template tagscvecve2017dreamboxedbxssbouqueteditor_projectvuln
CVSS vector: CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
CPE: cpe:2.3:a:bouqueteditor_project:bouqueteditor:2.0.0:*:*:*:*:dreambox:*:*
https://fireshellsecurity.team/assets/pdf/Vulnerability-XSS-Dreambox.pdf https://www.exploit-db.com/exploits/42986/ https://nvd.nist.gov/vuln/detail/CVE-2017-15287 https://github.com/ARPSyndicate/kenzer-templates
Source: ProjectDiscovery
References
3fireshellsecurity.team
https://fireshellsecurity.team/assets/pdf/Vulnerability-XSS-Dreambox.pdf nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2017-15287 42986exploit
https://www.exploit-db.com/exploits/42986