ZeroHour

CVE-2017-15287

PoC ×2
CVSS 3.0
6.1 medium
EPSS
6%p93
Published
()
Modified
Description

There is XSS in the BouquetEditor WebPlugin for Dream Multimedia Dreambox devices, as demonstrated by the "Name des Bouquets" field, or the file parameter to the /file URI.

Vendors
bouqueteditor project
Products
bouqueteditor
Weakness
CWE-79
Vector
CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N

In the news

No ingested article mentions this CVE yet.