vendor:
Super Backup
by:
Vulnerability Laboratory
7.1
CVSS
MEDIUM
Directory Traversal
22
CWE
Product Name: Super Backup
Affected Version From: 2.0.5
Affected Version To: 2.0.5
Patch Exists: NO
Related CWE: N/A
CPE: a:dropouts_technologies_llp:super_backup
Metasploit:
N/A
Other Scripts:
N/A
Platforms Tested: iOS
2020
Super Backup v2.0.5 iOS – Directory Traversal Vulnerability
A directory traversal web vulnerability has been discovered in the official Super Backup v2.0.5 ios mobile web-application. The vulnerability allows remote attackers to change the application path in performed requests to compromise the local application or file-system of a mobile device.
Mitigation:
Ensure that the application is not vulnerable to directory traversal attacks by validating user input and restricting access to sensitive files and directories.