Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1000 CNY

100.0%

CVE-2017-16567 PoC — Logitech Media Server 跨站脚本漏洞

Source
Associated Vulnerability
Title:Logitech Media Server 跨站脚本漏洞 (CVE-2017-16567)
Description:Persistent Cross-Site Scripting (XSS) vulnerability in Logitech Media Server 7.9.0, affecting the "Favorites" feature. This vulnerability allows remote attackers to inject and permanently store malicious JavaScript payloads, which are executed when users access the affected functionality. Exploitation of this vulnerability can lead to Session Hijacking and Credential Theft, Execution of unauthorized actions on behalf of users, and Exfiltration of sensitive data. This vulnerability presents a potential risk for widespread exploitation in connected IoT environments.
Readme
# CVE-2017-16567

1. Exploit Title: Logitech Media Server : Persistent Cross Site Scripting(XSS)
2. Shodan Dork: Search Logitech Media Server
3. Date: 11/03/2017
4. Exploit Author: Dewank Pant
5. Vendor Homepage: www.logitech.com
6. Version: 7.9.0
7. Tested on: Windows 10, Linux

 
 
 
POC:
 
1. Access and go to the favorites tab and add a new favorite.
2. Add script as the value of the field.
3. Payload : <script> alert(1)</script>
4. Script saved and gives a pop-up to user every time they access that page.

File Snapshot

[4.0K] /data/pocs/1638573db402567296185c336c9ce60b39c61ef8 └── [ 515] README.md 0 directories, 1 file
Shenlong Bot has cached this for you
Remarks
    1. It is advised to access via the original source first.
    2. Local POC snapshots are reserved for subscribers — if the original source is unavailable, the local mirror is part of the paid plan.
    3. Mirroring, verifying, and maintaining this POC archive takes ongoing effort, so local snapshots are a paid feature. Your subscription keeps the archive online — thank you for the support. View subscription plans →