9.8
CVSSv3

CVE-2017-12930

Published: 21/09/2017 Updated: 29/09/2017
CVSS v2 Base Score: 7.5 | Impact Score: 6.4 | Exploitability Score: 10
CVSS v3 Base Score: 9.8 | Impact Score: 5.9 | Exploitability Score: 3.9
VMScore: 760
Vector: AV:N/AC:L/Au:N/C:P/I:P/A:P

Vulnerability Summary

SQL Injection in the admin interface in TecnoVISION DLX Spot Player4 version >1.5.10 allows remote unauthenticated users to access the web interface as administrator via a crafted password.

Vulnerable Product Search on Vulmon Subscribe to Product

tecnovision dlx spot player4 -

Exploits

# Exploit Title: DlxSpot - Player4 LED video wall - Admin Interface SQL Injection # Google Dork: "DlxSpot - Player4" # Date: 2017-05-14 # Discoverer: Simon Brannstrom # Authors Website: unknownpwngithubio/ # Vendor Homepage: wwwtecnovisioncom/ # Software Link: n/a # Version: >1510 # Tested on: Linux # About: DlxSpot is the s ...
# Exploit Title: DlxSpot - Player4 LED video wall - Hardcoded Root SSH Password # Google Dork: "DlxSpot - Player4" # Date: 2017-05-14 # Discoverer: Simon Brannstrom # Authors Website: unknownpwngithubio/ # Vendor Homepage: wwwtecnovisioncom/ # Software Link: n/a # Version: All known versions # Tested on: Linux # About: DlxSpot i ...
DlxSpot Player4 LED video wall has a hardcoded password that allows you to ssh in and escalate to root ...
DlxSpot Player4 LED video wall suffers from a remote shell upload vulnerability Versions greater than 1510 are affected ...
DlxSpot Player4 LED video wall suffers from a remote SQL injection vulnerability that allows for authentication bypass Versions greater than 1510 are affected ...

Github Repositories

infosec enthusiast and madman

Tecnovision LED Video Wall Vulnerabilities and Exploits From SQLi to full root access Introduction: Tecnovision is a manufacturer of LED Video Walls used in arenas (For example, Twickenham Stadium), concert halls, shopping malls, as roadsigns and much much more DlxSpot Player 4 is the software controller for some of these LED walls These are the unpatched exploits that I ha