vendor:
Bluetooth Text Chat
by:
Vulnerability Laboratory
9,1
CVSS
CRITICAL
Remote Code Execution
94
CWE
Product Name: Bluetooth Text Chat
Affected Version From: 1.0
Affected Version To: 1.0
Patch Exists: NO
Related CWE: N/A
CPE: a:hytech_professionals:bluetooth_text_chat:1.0
Metasploit:
N/A
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: iOS
2014
Bluetooth Text Chat v1.0 iOS – Code Execution Vulnerability
The vulnerability allows an remote attackers to execute own malicious system specific codes to compromise the iOS mobile application. The vulnerability is located in the message body input and affects the bluetooth message listing. Remote attackers are able to inject own system specific codes in the bluetooth message listing to compromise mobile application.
Mitigation:
Input validation and sanitization should be implemented to prevent malicious code injection.