S4E just found a high-severity finding from top 10 tcp port service scan
PlatformPlansPartners
Resources
ToolsBlogDocs
Sign Up →
medium·Product Based Web Vulnerabilities·Updated Jan 3, 2024

CVE-2017-15287 Scanner

CVE-2017-15287 scanner - Cross-Site Scripting (XSS) vulnerability in BouquetEditor WebPlugin for Dream Multimedia Dreambox

Est. Time~10 seconds
Scan TypeSingle Scan
Targetsdomain, ipv4, subdomain
CostFree
2.4k
Times Used
continuous scan runs
4.1k
Continuously Checked
assets under CS
0
Vulnerabilities Found
confirmed findings
References
CVECVE-2017-15287
6.1
CVSS

There is XSS in the BouquetEditor WebPlugin for Dream Multimedia Dreambox devices, as demonstrated by the "Name des Bouquets" field, or the file parameter to the /file URI.

Attack Vector
-
Privileges Req.
-
User Interaction
-
Affected
n/aby n/a
n/a
Updated Aug 22, 2026View on NVD →
Detail

The BouquetEditor WebPlugin for Dream Multimedia Dreambox devices is a software tool used to edit and organize television channel bundles, or "bouquets." With this plugin, users can create custom bouquets and easily edit their existing ones. The plugin is particularly popular among Dreambox owners who use their device for satellite or cable TV.

One serious vulnerability that has been discovered in the BouquetEditor WebPlugin is CVE-2017-15287. This vulnerability allows attackers to inject malicious code into the "Name des Bouquets" field or the file parameter of the /file URI. By exploiting this vulnerability, attackers can execute arbitrary code on the affected device, potentially hijacking the system and gaining access to sensitive information.

If exploited, this vulnerability can lead to serious consequences for Dreambox owners, including the theft of personal or financial information. For example, an attacker might use this vulnerability to install malware that steals login credentials for online banking websites. In addition, an attacker could use the device as a gateway to launch further attacks on other devices connected to the same network.

Thanks to the powerful pro features of the s4e.io platform, readers of this article can quickly and easily learn about potential vulnerabilities in their digital assets. By leveraging the platform's advanced scanning tools and expert analysis, users can gain a deeper understanding of their security posture and take proactive steps to protect against threats, such as the CVE-2017-15287 vulnerability in the BouquetEditor WebPlugin.

 

REFERENCES

Solution Advice

Fortunately, there are several precautions that can be taken to protect against this vulnerability. These include:

  • Ensuring that the plugin software is up-to-date and running the latest version.
  • Reviewing and validating user input to ensure that it is free of malicious code.
  • Using strong and unique passwords for all user accounts.
  • Configuring the device to block all incoming traffic that is not explicitly authorized.
  • Limiting the use of the BouquetEditor WebPlugin to trusted and authenticated users only.

Get AI-powered remediation steps tailored to your asset.

Try AI Solutions →

Check your infrastructure.
Right now.

11,000+ scanners. Free to start. No credit card required.

CVE-2017-15287 scanner - Cross-Site Scripting (XSS) vulnerability in BouquetEditor WebPlugin for Dream Multimedia Dreambox | S4E