High severity8.8NVD Advisory· Published Sep 21, 2017· Updated May 13, 2026
CVE-2017-12929
CVE-2017-12929
Description
Arbitrary File Upload in resource.php of TecnoVISION DLX Spot Player4 version >1.5.10 allows remote authenticated users to upload arbitrary files leading to Remote Command Execution.
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
1- packetstormsecurity.com/files/144258/DlxSpot-Shell-Upload.htmlnvdExploitThird Party AdvisoryVDB Entry
News mentions
0No linked articles in our index yet.