vendor:
Wireless Photo Access
by:
Unknown
5.6
CVSS
MEDIUM
Multiple Vulnerabilities
20
CWE
Product Name: Wireless Photo Access
Affected Version From: 1.0.10
Affected Version To: 1.0.10
Patch Exists: NO
Related CWE: CVE-2013-2856, CVE-2013-2857, CVE-2013-2858
CPE: a:wireless_photo_access:wireless_photo_access:1.0.10
Metasploit:
https://www.rapid7.com/db/vulnerabilities/ubuntu-usn-2985-2/, https://www.rapid7.com/db/vulnerabilities/gentoo-linux-cve-2013-2856/, https://www.rapid7.com/db/vulnerabilities/google-chrome-cve-2013-2856/, https://www.rapid7.com/db/vulnerabilities/debian-DSA-2857/, https://www.rapid7.com/db/vulnerabilities/gentoo-linux-cve-2013-2857/, https://www.rapid7.com/db/vulnerabilities/google-chrome-cve-2013-2857/, https://www.rapid7.com/db/vulnerabilities/gentoo-linux-cve-2013-2858/, https://www.rapid7.com/db/vulnerabilities/google-chrome-cve-2013-2858/
Platforms Tested: iOS
2013
Wireless Photo Access 1.0.10 iOS – Multiple Vulnerabilities
Wireless Photo Access 1.0.10 iOS is prone to multiple vulnerabilities including arbitrary file upload, cross-site scripting and remote code execution vulnerabilities. These issues are due to a failure in the application to properly sanitize user-supplied input before using it in the context of an arbitrary code execution vulnerability. An attacker can exploit these issues to upload arbitrary files, execute arbitrary script code in the context of the affected site, steal cookie-based authentication credentials, and perform unauthorized actions. This may aid in launching further attacks.
Mitigation:
To mitigate these vulnerabilities, users are advised to update to the latest version of Wireless Photo Access and ensure that their iOS devices are running the latest version of iOS. Additionally, users should exercise caution when accessing and downloading files from untrusted sources.