vendor:
iPhone ishred
by:
Khashayar Fereidani
7.5
CVSS
HIGH
Directory Traversal
22
CWE
Product Name: iPhone ishred
Affected Version From: iPhone ishred 1.93
Affected Version To: iPhone ishred 1.93
Patch Exists: NO
Related CWE: N/A
CPE: N/A
Metasploit:
N/A
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: iPhone 4 (IOS 4.0.1)
2011
iPhone ishred 1.93 Directory Traversal
A directory traversal vulnerability exists in iPhone ishred 1.93. This vulnerability allows an attacker to access sensitive files on the system. The vulnerability is due to insufficient input validation when handling requests. An attacker can exploit this vulnerability by sending a specially crafted request containing directory traversal sequences. This will allow the attacker to access sensitive files on the system.
Mitigation:
Input validation should be performed to prevent directory traversal attacks.