vendor:
Photo Transfer 2
by:
Vulnerability Laboratory Research Team
3,4
CVSS
MEDIUM
Denial of Service
400
CWE
Product Name: Photo Transfer 2
Affected Version From: Photo Transfer 2 - v1.0 iOS
Affected Version To: Photo Transfer 2 - v1.0 iOS
Patch Exists: YES
Related CWE: N/A
CPE: a:arvin_brook:photo_transfer_2
Metasploit:
N/A
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: iOS
2015
Photo Transfer (2) v1.0 iOS – Denial of Service Vulnerability
A remote denial of service vulnerability has been discovered in the official Photo Transfer 2 - v1.0 iOS mobile web-application. The issue allows local attackers to crash or shutdown the software client by usage of special crafted payloads. The vulnerability is located in the id value restriction of show module path context. Remote attacker can easily crash the application remotly by including wrong and large id context in integer format.
Mitigation:
The vulnerability can be patched by a secure parse and encode of the vulnerable id value.