header-logo
Suggest Exploit
vendor:
Wireless Drive - Transfer & Share Files over WiFi
by:
Vulnerability Laboratory Research Team
6,8
CVSS
HIGH
Local File Include & Persistent Input Validation
94, 79
CWE
Product Name: Wireless Drive - Transfer & Share Files over WiFi
Affected Version From: 1.1.0
Affected Version To: 1.1.0
Patch Exists: YES
Related CWE: N/A
CPE: a:ondemandworld:wireless_drive
Metasploit: N/A
Other Scripts: N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References: N/A
Nuclei Metadata: N/A
Platforms Tested: iOS
2014

Wireless Drive v1.1.0 iOS – Multiple Web Vulnerabilities

The local file include web vulnerability allows remote attackers to include local files from the mobile device to compromise the application or mobile device. The vulnerability is located in the `file` value of the `index.php` file. Remote attackers are able to inject own malicious files to compromise the mobile device or application. The request method to inject is POST and the attack vector is located on the application-side of the service. The persistent input validation web vulnerability allows remote attackers to inject own malicious script codes to the application-side of the service. The vulnerability is located in the `name` value of the `index.php` file. Remote attackers are able to inject own malicious script codes to compromise the application or mobile device. The request method to inject is POST and the attack vector is located on the application-side of the service.

Mitigation:

Update to the latest version of the application and apply the necessary security patches.
Source

Exploit-DB raw data: