header-logo
Suggest Exploit
vendor:
Easy File Manager
by:
Vulnerability Laboratory Research Team
7,9
CVSS
HIGH
Persistent Input Validation
20
CWE
Product Name: Easy File Manager
Affected Version From: Easy File Manager v1.1 iOS
Affected Version To: Easy File Manager v1.1 iOS
Patch Exists: YES
Related CWE: N/A
CPE: a:easytime_studio:easy_file_manager:1.1
Metasploit: N/A
Other Scripts: N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References: N/A
Nuclei Metadata: N/A
Platforms Tested: iOS
2014

Easy FileManager 1.1 iOS – Multiple Web Vulnerabilities

Multiple persistent input validation vulnerabilities are detected in the Easytime Studio Easy File Manager v1.1 mobile web-application. The vulnerabilities are located in the `name` and `path` value of the `upload` and `create` module. Remote attackers are able to inject own malicious script codes to the application-side of the vulnerable module. The request method to inject is POST and the attack vector is located on the application-side. The security risk of the persistent input validation vulnerabilities are estimated as high with a cvss (common vulnerability scoring system) count of 7.9. Exploitation of the persistent input validation vulnerability requires a low privilege web-application user account and low user interaction. Successful exploitation of the vulnerability results in session hijacking, persistent phishing attacks, persistent external redirects to malicious source and persistent manipulation of affected or connected module context.

Mitigation:

The vulnerability can be patched by a secure parse and encode of the vulnerable name and path value. Restrict the input and disallow special chars.
Source

Exploit-DB raw data: