vendor:
iPhone OS
by:
theSmallNothing
7.5
CVSS
HIGH
Directory Traversal
22
CWE
Product Name: iPhone OS
Affected Version From: 2.8
Affected Version To: 2.8
Patch Exists: YES
Related CWE: N/A
CPE: a:apple:iphone_os
Metasploit:
N/A
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: iPod Touch 2G (4.1)
2011
iPod Touch/iPhone iFileExplorer Free Directory Traversal
This exploit allows an attacker to traverse the directory structure of an iPod Touch/iPhone device running the iFileExplorer application. The exploit is achieved by sending a crafted URL to the device, which allows the attacker to access the AddressBook.sqlitedb file. The attacker can then use SQLite commands to extract the address book information from the device.
Mitigation:
Ensure that the iFileExplorer application is not installed on the device, and that the device is running the latest version of the iOS operating system.