vendor:
DNS4Me
by:
7.5
CVSS
HIGH
Denial of Service, Cross-Site Scripting
400, 79
CWE
Product Name: DNS4Me
Affected Version From: Version 3.0.0.4
Affected Version To: Unknown
Patch Exists: NO
Related CWE:
CPE: a:dns4me:dns4me:3.0.0.4
Platforms Tested:
Denial of Service and Cross-Site Scripting Vulnerabilities in DNS4Me
DNS4Me is susceptible to a denial of service vulnerability where attackers can cause the web server to consume all available CPU resources and crash the application. Additionally, there is a cross-site scripting vulnerability due to the application's failure to properly sanitize user-supplied URI input. This allows remote attackers to create malicious URI links containing hostile HTML and script code, which can be rendered in the victim's web browser, potentially leading to theft of authentication credentials or other attacks.
Mitigation:
It is recommended to update to the latest version of DNS4Me to mitigate these vulnerabilities. Additionally, input validation and sanitization should be implemented to prevent cross-site scripting attacks.