Record summary

CVE-2017-17737 has a selected CVSS score of 6.1 (medium); EIP currently links 1 catalogued exploit.

Description

The BrightSign Digital Signage (4k242) device (Firmware 6.2.63 and below) has XSS via the REF parameter to /network_diagnostics.html or /storage_info.html.

Description source: CVE List

Exploitation context

Available material

Catalogued exploits
1

Proofs of concept

1

Catalogued exploits

ExploitDBBrightSign Digital Signage - Multiple VulnerablitiesExploitDB exploitby Information ParadoxNot analyzed1 file

linked to 3 vulnerabilities

ExploitDB

PoC details

References

3