CVE-2017-12929
HIGHTecnoVISION DLX Spot Player4 >1.5.10 - Authenticated Arbitrary File Upload via resource.php
Title source: llmExploitation Summary
EIP tracks 2 public exploits for CVE-2017-12929. PoCs published by Simon Brannstrom.
AI-analyzed exploit summary This exploit demonstrates an arbitrary file upload vulnerability in DlxSpot - Player4 LED video wall software, leading to remote command execution (RCE). The attacker uploads a malicious PHP shell via `resource.php` and executes commands through a crafted HTTP request.
Description
Arbitrary File Upload in resource.php of TecnoVISION DLX Spot Player4 version >1.5.10 allows remote authenticated users to upload arbitrary files leading to Remote Command Execution.
Exploits (2)
This exploit demonstrates an arbitrary file upload vulnerability in DlxSpot - Player4 LED video wall software, leading to remote command execution (RCE). The attacker uploads a malicious PHP shell via `resource.php` and executes commands through a crafted HTTP request.
This is a technical writeup detailing hardcoded SSH credentials (dlxuser:tecn0visi0n) in DlxSpot Player4 LED video wall software, allowing authentication bypass and privilege escalation to root. The vulnerability is confirmed in all known versions, with no patch available.
References (1)
Scores
CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H