Exploitation Summary
EIP tracks 1 public exploit for CVE-2017-17738. PoCs published by Information Paradox.
AI-analyzed exploit summary The writeup describes multiple vulnerabilities in BrightSign Digital Signage (Firmware 6.2.63 and below), including XSS, directory traversal, and unauthenticated file upload/modification. These can be combined to compromise the device and end users.
Description
The BrightSign Digital Signage (4k242) device (Firmware 6.2.63 and below) allows renaming and modifying files via /tools.html.
Exploits (1)
The writeup describes multiple vulnerabilities in BrightSign Digital Signage (Firmware 6.2.63 and below), including XSS, directory traversal, and unauthenticated file upload/modification. These can be combined to compromise the device and end users.
References (2)
Scores
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N