vendor:
DlxSpot - Player4
by:
Simon Brannstrom
9,8
CVSS
CRITICAL
Arbitrary File Upload leading to Remote Command Execution
434
CWE
Product Name: DlxSpot - Player4
Affected Version From: >1.5.10
Affected Version To: N/A
Patch Exists: NO
Related CWE: CVE-2017-12929, CVE-2017-12928, CVE-2017-12930
CPE: a:tecnovision:dlxspot_-_player4
Metasploit:
N/A
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: Linux
2017
DlxSpot – Player4 LED video wall – Arbitrary File Upload to RCE
A vulnerability in DlxSpot - Player4 LED video wall allows an attacker to upload a malicious PHP shell and execute arbitrary commands on the system. This can be done by visiting http://host/resource.php and uploading a PHP shell, such as <?php system($_GET["c"]); ?>. The attacker can then execute arbitrary commands on the system by visiting http://host/resource/source/shell.php?c=id.
Mitigation:
The vendor has not released a patch for this vulnerability. Users should restrict access to the vulnerable system and monitor for suspicious activity.