vendor:
PhotoSync Wifi&Bluetooth
by:
Vulnerability Laboratory Research Team
6,8
CVSS
HIGH
Local File Include
98
CWE
Product Name: PhotoSync Wifi&Bluetooth
Affected Version From: 1.0
Affected Version To: 1.0
Patch Exists: NO
Related CWE: N/A
CPE: a:haixia_liu:photossync_wifi_bluetooth
Metasploit:
N/A
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: iOS
2014
PhotoSync Wifi & Bluetooth v1.0 – File Include Vulnerability
A local file include web vulnerability has been discovered in the official PhotoSync Wifi&Bluetooth 1.0 iOS mobile application. The local file include web vulnerability allows remote attackers to unauthorized include local file/path requests or system specific path commands to compromise the mobile web-application.
Mitigation:
Ensure that user input is properly sanitized and validated before being used in the application.