vendor:
WiFi HD
by:
Wh1t3Rh1n0 (Michael Allen)
7.5
CVSS
HIGH
Directory Traversal and Denial of Service
22
CWE
Product Name: WiFi HD
Affected Version From: 8.1
Affected Version To: 8.1
Patch Exists: NO
Related CWE: N/A
CPE: a:savysoda:wifi_hd
Metasploit:
N/A
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: iPhone
2015
WiFi HD 8.1 – Directory Traversal and Denial of Service
The web server (titled "WiFi" in the app) is vulnerable to multiple directory traversal issues which allow an attacker to download, upload, create, or delete any file to which the app has access. The SMB server (titled "Shared Folder") is vulnerable to a Denial of Service attack when issued the command, "dir -c", within smbclient. It also discloses a listing of all readable files within the iPhone's file system via the IPC$ share.
Mitigation:
The vendor should patch the application to prevent directory traversal and denial of service attacks.