Skip to main content

Vendor/product archive

tecnovision / dlx_spot_player4 CVEs

Beta · best-effort

3 CVEs tagged to tecnovision / dlx_spot_player42 Critical, 1 High, 0 Medium, 0 Low, 0 Unrated.

CVE-2017-12930

Published Sep 21, 2017

SQL Injection in the admin interface in TecnoVISION DLX Spot Player4 version >1.5.10 allows remote unauthenticated users to access the web interface as administrator via a crafted…

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2017-12929

Published Sep 21, 2017

Arbitrary File Upload in resource.php of TecnoVISION DLX Spot Player4 version >1.5.10 allows remote authenticated users to upload arbitrary files leading to Remote Command Executi…

CVSS 8.8 · High
Vendor/product tagsBeta · best-effort

CVE-2017-12928

Published Sep 21, 2017

A hard-coded password of tecn0visi0n for the dlxuser account in TecnoVISION DLX Spot Player4 (all known versions) allows remote attackers to log in via SSH and escalate privileges…

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort
Showing 1-3 of 3 CVEsPage 1 of 1