vendor:
DlxSpot
by:
Simon Brannstrom
8.8
CVSS
HIGH
SQL Injection
89
CWE
Product Name: DlxSpot
Affected Version From: Version 1.5.10
Affected Version To: All versions below 1.5.10
Patch Exists: NO
Related CWE: CVE-2017-12930, CVE-2017-12928, CVE-2017-12929
CPE: a:tecnovision:dlxspot
Platforms Tested: Linux
2017
DlxSpot – Player4 LED video wall – Admin Interface SQL Injection
DlxSpot Player 4 above version 1.5.10 suffers from an SQL injection vulnerability in the admin interface login and is exploitable using the username:admin and password:x' or 'x'='x.
Mitigation:
Update to a version higher than 1.5.10, or apply patches provided by the vendor.