vendor:
iDocManager
by:
R3d@l3rt, Sp@2K, Sunlight, H@ckk3y
7.5
CVSS
HIGH
Directory Traversal
22
CWE
Product Name: iDocManager
Affected Version From: 1.0.0
Affected Version To: 1.0.0
Patch Exists: NO
Related CWE: N/A
CPE: a:apple:idocmanager
Metasploit:
N/A
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: iPhone, iPod 3GS with 4.2.1 firmware
2011
iDocManager v1.0.0 for iPhone / iPod touch, Directory Traversal
There is directory traversal vulnerability in the iDocManager. Exploit Testing involves using FTP to connect to the server and using the 'get' command to traverse the directory and access the passwd and com.apple.conference.plist files.
Mitigation:
Ensure that user input is validated and sanitized to prevent directory traversal attacks.