3.5
CVSSv2

CVE-2017-16567

Published: 10/11/2017 Updated: 28/11/2017
CVSS v2 Base Score: 3.5 | Impact Score: 2.9 | Exploitability Score: 6.8
CVSS v3 Base Score: 5.4 | Impact Score: 2.7 | Exploitability Score: 2.3
VMScore: 355
Vector: AV:N/AC:M/Au:S/C:N/I:P/A:N

Vulnerability Summary

Cross-site scripting (XSS) vulnerability in Logitech Media Server 7.9.0 allows remote malicious users to inject arbitrary web script or HTML via a "favorite."

Vulnerable Product Search on Vulmon Subscribe to Product

logitech media server 7.9.0

Exploits

# Exploit Title: Logitech Media Server : Persistent Cross Site Scripting(XSS) # Shodan Dork: Search Logitech Media Server # Date: 11/03/2017 # Exploit Author: Dewank Pant # Vendor Homepage: wwwlogitechcom # Software Link: [download link if available] # Version: 790 # Tested on: Windows 10, Linux # CVE : Applied For POC: Access and go to th ...

Github Repositories

CVE-2017-16567 Exploit Title: Logitech Media Server : Persistent Cross Site Scripting(XSS) Shodan Dork: Search Logitech Media Server Date: 11/03/2017 Exploit Author: Dewank Pant Vendor Homepage: wwwlogitechcom Version: 790 Tested on: Windows 10, Linux POC: Access and go to the favorites tab and add a new favorite Add script as the value of the field Payload : <s