vendor:
IPMap
by:
Vulnerability Laboratory Research Team
6,3
CVSS
CRITICAL
Arbitrary File Upload
434
CWE
Product Name: IPMap
Affected Version From: IPMap v2.5
Affected Version To: IPMap v2.5
Patch Exists: NO
Related CWE: N/A
CPE: a:apple:ipmap
Metasploit:
N/A
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: iPad, iPhone
2013
IPMap v2.5 iPad iPhone – Arbitrary File Upload Web Vulnerabilities
The Vulnerability Laboratory Research Team discovered an arbitrary file upload vulnerability in the mobile IPMap v2.5 app for the apple ipad & iphone. The vulnerability allows remote attackers via POST method to inject local app webserver folders to request unauthorized local webserver files.
Mitigation:
The vulnerability can be patched by a secure parse and encode of the vulnerable filename parameter.