PT-2018-16864 · Unknown · Photos In Wifi
Benjamin Kunz Mejri
·
Publicado
2018-01-08
·
Atualizado
2018-01-29
·
CVE-2018-5283
CVSS v3.1
7.5
Alta
| Vetor | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
Photos in Wifi application version 1.0.1
Description
The issue concerns directory traversal in the Photos in Wifi application. It is possible to exploit this via the
ext parameter to access files outside the intended directory, specifically through the assets-library://asset/asset.php endpoint.Recommendations
For version 1.0.1, avoid using the
ext parameter in the affected endpoint until the issue is resolved. As a temporary workaround, consider restricting access to the assets-library://asset/asset.php endpoint to minimize the risk of exploitation.Exploit
Correção
Path traversal
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Enumeração de Fraquezas
Identificadores relacionados
Produtos afetados
Photos In Wifi