vendor:
iPhone Folders
by:
Khashayar Fereidani
8.8
CVSS
HIGH
Directory Traversal
22
CWE
Product Name: iPhone Folders
Affected Version From: 2.5
Affected Version To: 2.5
Patch Exists: Yes
Related CWE: N/A
CPE: a:apple:iphone_folders
Metasploit:
N/A
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: iPhone 4 (IOS 4.0.1)
2011
iPhone Folders 2.5 Directory Traversal
This exploit allows an attacker to access sensitive files on an iPhone running iPhone Folders 2.5. The exploit uses a directory traversal vulnerability to access files such as the AddressBook.sqlitedb, Safari favorites, user email info, network info, and the passwd file. The exploit is written in Python and requires the user to enter the address of the iPhone and the file they wish to access.
Mitigation:
The vendor has released an update to address this vulnerability.