CVE-2017-12930
CRITICALTecnoVISION DLX Spot Player4 >1.5.10 - Unauthenticated SQL Injection via Admin Interface
Title source: llmExploitation Summary
EIP tracks 2 public exploits for CVE-2017-12930. PoCs published by Simon Brannstrom.
AI-analyzed exploit summary This is a technical writeup detailing an SQL injection vulnerability in DlxSpot Player4's admin interface login. It provides the exploit payload and a timeline of disclosure efforts.
Description
SQL Injection in the admin interface in TecnoVISION DLX Spot Player4 version >1.5.10 allows remote unauthenticated users to access the web interface as administrator via a crafted password.
Exploits (2)
This is a technical writeup detailing an SQL injection vulnerability in DlxSpot Player4's admin interface login. It provides the exploit payload and a timeline of disclosure efforts.
This writeup discloses hardcoded SSH credentials (dlxuser:tecn0visi0n) for DlxSpot Player4 LED video wall software, allowing authentication bypass and privilege escalation to root. No exploit code is provided, only credentials and a timeline of disclosure.
References (1)
Scores
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H