메뉴 건너뛰기

GREATUSER

cve

CVE-2017-15091

관리자 2018.01.25 04:00 조회 수 : 178

An issue has been found in the API component of PowerDNS Authoritative 4.x up to and including 4.0.4 and 3.x up to and including 3.4.11, where some operations that have an impact on the state of the server are still allowed even though the API has been configured as read-only via the api-readonly keyword. This missing check allows an attacker with valid API credentials to flush the cache, trigger a zone transfer or send a NOTIFY.


원문출처 : https://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2017-15091
번호 제목 글쓴이 날짜 조회 수
137 CVE-2016-10317 관리자 2017.04.04 142
136 CVE-2014-3929 관리자 2017.04.04 142
135 CVE-2014-3927 관리자 2017.04.04 142
134 CVE-2018-6001 관리자 2018.01.25 141
133 CVE-2017-0095 관리자 2017.03.18 141
132 CVE-2016-6992 관리자 2016.10.14 141
131 CVE-2017-15107 관리자 2018.01.25 140
130 CVE-2017-18045 관리자 2018.01.25 140
129 CVE-2017-14096 관리자 2018.01.25 140
128 CVE-2017-12809 (qemu) 관리자 2017.08.27 140
127 CVE-2018-5960 관리자 2018.01.25 139
126 CVE-2017-2912 관리자 2017.11.09 139
125 CVE-2017-16565 관리자 2017.11.09 139
124 CVE-2017-0079 관리자 2017.03.18 139
123 CVE-2014-7859 관리자 2017.08.27 138
위로