4.3
CVSSv2

CVE-2017-15687

Published: 23/10/2017 Updated: 17/11/2017
CVSS v2 Base Score: 4.3 | Impact Score: 2.9 | Exploitability Score: 8.6
CVSS v3 Base Score: 6.1 | Impact Score: 2.7 | Exploitability Score: 2.8
VMScore: 435
Vector: AV:N/AC:M/Au:N/C:N/I:P/A:N

Vulnerability Summary

DOM Based Cross Site Scripting (XSS) exists in Logitech Media Server 7.7.1, 7.7.2, 7.7.3, 7.7.5, 7.7.6, 7.9.0, and 7.9.1 via a crafted URI.

Vulnerable Product Search on Vulmon Subscribe to Product

logitech media server 7.7.6

logitech media server 7.9.0

logitech media server 7.9.1

logitech media server 7.7.2

logitech media server 7.7.5

logitech media server 7.7.1

logitech media server 7.7.3

Exploits

# Exploit Title: DOM Based Cross Site Scripting (XSS) - Logitech Media Server # Shodan Dork: Logitech Media Server # Date: 14/10/2017 # Exploit Author: Thiago "THX" Sena # Vendor Homepage: wwwlogitechcom # Tested on: windows 10 # CVE : CVE-2017-15687 ----------------------------------------------- PoC: - First you go to ( IP:PO ...