Dream Multimedia Dreambox devices via their WebControl component are vulnerable to reflected cross-site scripting, as demonstrated by the “Name des Bouquets” field, or the file parameter to the /file URI.
View the template here CVE-2017-15287.yaml
References:
https://www.exploit-db.com/exploits/42986/