vendor:
Photorange
by:
Vulnerability Laboratory
6,3
CVSS
HIGH
Local File Include
98
CWE
Product Name: Photorange
Affected Version From: Photorange v1.0 iOS
Affected Version To: Photorange v1.0 iOS
Patch Exists: YES
Related CWE: CVE-2014-6388
CPE: a:jiajun_kuang:photorange:1.0
Metasploit:
N/A
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: iOS
2014
Photorange v1.0 iOS – File Include Web Vulnerability
A local file include web vulnerability has been discovered in the official Photorange v1.0 iOS mobile web-application. The local file include web vulnerability allows remote attackers to unauthorized include local file/path requests or system specific path commands to compromise the mobile web-application.
Mitigation:
The vulnerability can be patched by a secure parse and encode of the vulnerable `filename` value in the `add file` module.