ID

VAR-201506-0121


CVE

CVE-2015-4714


TITLE

Dream Multimedia DreamBox DM500-S Cross-Site Scripting Vulnerability

Trust: 1.2

sources: CNVD: CNVD-2015-03923 // CNNVD: CNNVD-201506-354

DESCRIPTION

Cross-site scripting (XSS) vulnerability in the DreamBox DM500-S allows remote attackers to inject arbitrary web script or HTML via the mode parameter to /body. Dream Multimedia DreamBox DM500-S is a Linux-based digital TV set-top box receiver from Dream Multimedia, Germany. A cross-site scripting vulnerability exists in Dream Multimedia DreamBox DM500-S. An attacker may leverage this issue to execute arbitrary script code in the browser of an unsuspecting user in the context of the affected site. This may allow the attacker to steal cookie-based authentication credentials and launch other attacks

Trust: 2.52

sources: NVD: CVE-2015-4714 // JVNDB: JVNDB-2015-003236 // CNVD: CNVD-2015-03923 // BID: 75388 // VULHUB: VHN-82675

IOT TAXONOMY

category:['Network device']sub_category: -

Trust: 0.6

sources: CNVD: CNVD-2015-03923

AFFECTED PRODUCTS

vendor:dream propertymodel:dm500-sscope: - version: -

Trust: 1.6

vendor:dream multimedia tvmodel:dreambox dm500-sscope:eqversion:*

Trust: 1.0

vendor:dream multimediamodel:dreambox dm500-sscope: - version: -

Trust: 0.6

vendor:dream multimedia tvmodel:dreambox dm500-sscope: - version: -

Trust: 0.6

vendor:dream multimedia tvmodel:dreambox dm500sscope:eqversion:0

Trust: 0.3

sources: CNVD: CNVD-2015-03923 // BID: 75388 // JVNDB: JVNDB-2015-003236 // CNNVD: CNNVD-201506-354 // NVD: CVE-2015-4714

CVSS

SEVERITY

CVSSV2

CVSSV3

nvd@nist.gov: CVE-2015-4714
value: MEDIUM

Trust: 1.0

NVD: CVE-2015-4714
value: MEDIUM

Trust: 0.8

CNVD: CNVD-2015-03923
value: MEDIUM

Trust: 0.6

CNNVD: CNNVD-201506-354
value: MEDIUM

Trust: 0.6

VULHUB: VHN-82675
value: MEDIUM

Trust: 0.1

nvd@nist.gov: CVE-2015-4714
severity: MEDIUM
baseScore: 4.3
vectorString: AV:N/AC:M/AU:N/C:N/I:P/A:N
accessVector: NETWORK
accessComplexity: MEDIUM
authentication: NONE
confidentialityImpact: NONE
integrityImpact: PARTIAL
availabilityImpact: NONE
exploitabilityScore: 8.6
impactScore: 2.9
acInsufInfo: NONE
obtainAllPrivilege: NONE
obtainUserPrivilege: NONE
obtainOtherPrivilege: NONE
userInteractionRequired: NONE
version: 2.0

Trust: 1.8

CNVD: CNVD-2015-03923
severity: MEDIUM
baseScore: 4.3
vectorString: AV:N/AC:M/AU:N/C:N/I:P/A:N
accessVector: NETWORK
accessComplexity: MEDIUM
authentication: NONE
confidentialityImpact: NONE
integrityImpact: PARTIAL
availabilityImpact: NONE
exploitabilityScore: 8.6
impactScore: 2.9
acInsufInfo: NONE
obtainAllPrivilege: NONE
obtainUserPrivilege: NONE
obtainOtherPrivilege: NONE
userInteractionRequired: NONE
version: 2.0

Trust: 0.6

VULHUB: VHN-82675
severity: MEDIUM
baseScore: 4.3
vectorString: AV:N/AC:M/AU:N/C:N/I:P/A:N
accessVector: NETWORK
accessComplexity: MEDIUM
authentication: NONE
confidentialityImpact: NONE
integrityImpact: PARTIAL
availabilityImpact: NONE
exploitabilityScore: 8.6
impactScore: 2.9
acInsufInfo: NONE
obtainAllPrivilege: NONE
obtainUserPrivilege: NONE
obtainOtherPrivilege: NONE
userInteractionRequired: NONE
version: 2.0

Trust: 0.1

sources: CNVD: CNVD-2015-03923 // VULHUB: VHN-82675 // JVNDB: JVNDB-2015-003236 // CNNVD: CNNVD-201506-354 // NVD: CVE-2015-4714

PROBLEMTYPE DATA

problemtype:CWE-79

Trust: 1.9

sources: VULHUB: VHN-82675 // JVNDB: JVNDB-2015-003236 // NVD: CVE-2015-4714

THREAT TYPE

remote

Trust: 0.6

sources: CNNVD: CNNVD-201506-354

TYPE

XSS

Trust: 0.6

sources: CNNVD: CNNVD-201506-354

CONFIGURATIONS

sources: JVNDB: JVNDB-2015-003236

EXPLOIT AVAILABILITY

sources: VULHUB: VHN-82675

PATCH

title:DreamBoxurl:http://www.dream-multimedia-tv.de/

Trust: 0.8

sources: JVNDB: JVNDB-2015-003236

EXTERNAL IDS

db:NVDid:CVE-2015-4714

Trust: 3.4

db:PACKETSTORMid:132214

Trust: 3.1

db:BIDid:75388

Trust: 2.0

db:JVNDBid:JVNDB-2015-003236

Trust: 0.8

db:CNNVDid:CNNVD-201506-354

Trust: 0.7

db:CNVDid:CNVD-2015-03923

Trust: 0.6

db:VULHUBid:VHN-82675

Trust: 0.1

sources: CNVD: CNVD-2015-03923 // VULHUB: VHN-82675 // BID: 75388 // JVNDB: JVNDB-2015-003236 // CNNVD: CNNVD-201506-354 // NVD: CVE-2015-4714

REFERENCES

url:http://packetstormsecurity.com/files/132214/dreambox-dm500s-cross-site-scripting.html

Trust: 3.1

url:http://www.securityfocus.com/bid/75388

Trust: 1.1

url:http://cve.mitre.org/cgi-bin/cvename.cgi?name=cve-2015-4714

Trust: 0.8

url:http://web.nvd.nist.gov/view/vuln/detail?vulnid=cve-2015-4714

Trust: 0.8

url:http://www.dream-multimedia-tv.de/english/products_dm500.php

Trust: 0.3

sources: CNVD: CNVD-2015-03923 // VULHUB: VHN-82675 // BID: 75388 // JVNDB: JVNDB-2015-003236 // CNNVD: CNNVD-201506-354 // NVD: CVE-2015-4714

CREDITS

Jay Turla

Trust: 0.3

sources: BID: 75388

SOURCES

db:CNVDid:CNVD-2015-03923
db:VULHUBid:VHN-82675
db:BIDid:75388
db:JVNDBid:JVNDB-2015-003236
db:CNNVDid:CNNVD-201506-354
db:NVDid:CVE-2015-4714

LAST UPDATE DATE

2025-04-13T23:22:28.205000+00:00


SOURCES UPDATE DATE

db:CNVDid:CNVD-2015-03923date:2015-06-24T00:00:00
db:VULHUBid:VHN-82675date:2016-12-07T00:00:00
db:BIDid:75388date:2015-06-24T00:00:00
db:JVNDBid:JVNDB-2015-003236date:2015-06-24T00:00:00
db:CNNVDid:CNNVD-201506-354date:2015-06-23T00:00:00
db:NVDid:CVE-2015-4714date:2025-04-12T10:46:40.837

SOURCES RELEASE DATE

db:CNVDid:CNVD-2015-03923date:2015-06-24T00:00:00
db:VULHUBid:VHN-82675date:2015-06-22T00:00:00
db:BIDid:75388date:2015-06-24T00:00:00
db:JVNDBid:JVNDB-2015-003236date:2015-06-24T00:00:00
db:CNNVDid:CNNVD-201506-354date:2015-06-23T00:00:00
db:NVDid:CVE-2015-4714date:2015-06-22T18:59:02.120