vendor:
My Assistant
by:
Vulnerability Laboratory Research Team
6,9
CVSS
HIGH
Local File Include
98
CWE
Product Name: My Assistant
Affected Version From: 1.1
Affected Version To: 1.1
Patch Exists: YES
Related CWE: N/A
CPE: a:tigercom:my_assistant:1.1
Metasploit:
N/A
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: iOS
2014
TigerCom My Assistant v1.1 iOS – File Include Vulnerability
A local file include web vulnerability has been discovered in the official TigerCom My Assistant v1.1 iOS mobile web-application. The vulnerability allows local attackers to inject malicious script codes to application-side of the vulnerable service. The vulnerability is located in the `file` value of the `index.php` file. Local attackers are able to inject own malicious script codes to application-side of the vulnerable service. The request method to inject is POST and the attack vector is local.
Mitigation:
The vulnerability can be patched by a secure parse and encode of the vulnerable file parameter.