A cross-site scripting issue has been found in the web interface of PowerDNS Recursor from 4.0.0 up to and including 4.0.6, where the qname of DNS queries was displayed without any escaping, allowing a remote attacker to inject HTML and Javascript code into the web interface, altering the content.
Metrics
Affected Vendors & Products
References
History
No history.
MITRE
Status: PUBLISHED
Assigner: redhat
Published: 2018-01-23T15:00:00Z
Updated: 2024-09-17T03:27:42.169Z
Reserved: 2017-10-08T00:00:00
Link: CVE-2017-15092
Vulnrichment
No data.
NVD
Status : Modified
Published: 2018-01-23T15:29:00.323
Modified: 2019-10-09T23:24:12.110
Link: CVE-2017-15092
Redhat
No data.