VYPR
High severity8.8NVD Advisory· Published Sep 21, 2017· Updated May 13, 2026

CVE-2017-12929

CVE-2017-12929

Description

Arbitrary File Upload in resource.php of TecnoVISION DLX Spot Player4 version >1.5.10 allows remote authenticated users to upload arbitrary files leading to Remote Command Execution.

Patches

0

No patches discovered yet.

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

References

1

News mentions

0

No linked articles in our index yet.