vendor:
Easy Transfer Wifi Transfer
by:
Vulnerability Laboratory
7.1
CVSS
MEDIUM
Directory Traversal
22
CWE
Product Name: Easy Transfer Wifi Transfer
Affected Version From: Easy Transfer v1.7 iOS
Affected Version To: Easy Transfer v1.7 iOS
Patch Exists: YES
Related CWE: N/A
CPE: a:rubikon_teknoloji:easy_transfer_wifi_transfer:1.7
Metasploit:
N/A
Other Scripts:
N/A
Platforms Tested: iOS
2020
Easy Transfer v1.7 iOS – Multiple Web Vulnerabilities
A directory traversal web vulnerability has been discovered in the Easy Transfer Wifi Transfer v1.7 ios mobile application. The vulnerability allows remote attackers to change the application path in performed requests to compromise the local application or file-system of a mobile device. Attackers are for example able to request environment variables or a sensitive system path.
Mitigation:
The vulnerability can be patched by a secure parse and encode of the application path request.