| Vulnerability Name: | CVE-2004-0606 (CCN-16456) | ||||||||
| Assigned: | 2004-06-18 | ||||||||
| Published: | 2004-06-18 | ||||||||
| Updated: | 2017-07-11 | ||||||||
| Summary: | Cross-site scripting (XSS) vulnerability in Infoblox DNS One running firmware 2.4.0-8 and earlier allows remote attackers to execute arbitrary scripts as other users via the (1) CLIENTID or (2) HOSTNAME option of a DHCP request. | ||||||||
| CVSS v3 Severity: | 5.6 Medium (CCN CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:L)
| ||||||||
| CVSS v2 Severity: | 6.8 Medium (CVSS v2 Vector: AV:N/AC:M/Au:N/C:P/I:P/A:P)
| ||||||||
| Vulnerability Type: | CWE-Other | ||||||||
| Vulnerability Consequences: | Obtain Information | ||||||||
| References: | Source: CCN Type: BugTraq Mailing List, Fri Jun 18 2004 - 20:38:30 CDT Script injection in DNSONE appliance Source: MITRE Type: CNA CVE-2004-0606 Source: BUGTRAQ Type: UNKNOWN 20040619 Script injection in DNSONE appliance Source: CCN Type: DNS One Web page DNS One Network Identity Appliance - DNS Appliance, DHCP Appliance, DNS Server, DHCP Server Source: CCN Type: OSVDB ID: 7186 Infoblox DNS One Log Multiple Parameter XSS Source: BID Type: Vendor Advisory 10573 Source: CCN Type: BID-10573 Infoblox DNS One Script Injection Vulnerability Source: XF Type: UNKNOWN dnsone-dhcp-report-xss(16456) Source: XF Type: UNKNOWN dnsone-dhcp-report-xss(16456) | ||||||||
| Vulnerable Configuration: | Configuration 1: Denotes that component is vulnerable | ||||||||
| BACK | |||||||||