vendor:
Foto Uebertraeger
by:
Vulnerability Laboratory Research Team
6,3
CVSS
HIGH
File Include Vulnerability
94
CWE
Product Name: Foto Uebertraeger
Affected Version From: GS Foto Uebertraeger v3.0 iOS
Affected Version To: GS Foto Uebertraeger v3.0 iOS
Patch Exists: YES
Related CWE: N/A
CPE: N/A
Metasploit:
N/A
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: iOS
2014
GS Foto Uebertraeger v3.0 iOS – File Include Vulnerability
A local file include web vulnerability has been discovered in the official Golden Soft Photo/Foto Uebertraeger v3.0 iOS mobile application. The local file include web vulnerability allows remote attackers to unauthorized include local file/path requests or system specific path commands to compromise the mobile web-application.
Mitigation:
The vulnerability can be patched by a secure parse and encode of the vulnerable filename and albumname values.