vendor:
TIOD v1.3.3 for iPhone / iPod touch
by:
R3d@l3rt, H@ckk3y
7.5
CVSS
HIGH
Directory Traversal
22
CWE
Product Name: TIOD v1.3.3 for iPhone / iPod touch
Affected Version From: 1.3.2003
Affected Version To: 1.3.2003
Patch Exists: NO
Related CWE: N/A
CPE: a:tiod:tiod_v1.3.3_for_iphone_/ipod_touch
Metasploit:
N/A
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: iPhone, iPod 3GS with 4.2.1 firmware
2011
TIOD v1.3.3 for iPhone / iPod touch, Directory Traversal
There is directory traversal vulnerability in the TIOD. Exploit Testing involves connecting to the server via FTP and using the 'dir' and 'get' commands to traverse the directory structure and retrieve the 'passwd' file.
Mitigation:
Ensure that user input is properly validated and sanitized to prevent directory traversal attacks.