vendor:
WK UDID
by:
Vulnerability Laboratory Research Team
5.6
CVSS
MEDIUM
Command Injection
78
CWE
Product Name: WK UDID
Affected Version From: 1.0.1
Affected Version To: 1.0.1
Patch Exists: YES
Related CWE: N/A
CPE: a:wk_edv_gmbh:wk_udid
Metasploit:
N/A
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: iOS
2015
WK UDID v1.0.1 iOS – Command Inject Vulnerability
The Vulnerability Laboratory Research team discovered a local command inject web vulnerability in the official WK UDID v1.0.1 iOS mobile web-application. The vulnerability allows to inject malicious script codes to the application-side of the vulnerable mobile app. The vulnerability is located in the device name value of the send by mail function. Local attackers are able to manipulate the name value of the device to compromise the mail function of the wkudid mobil app.
Mitigation:
Restrict access to the vulnerable application and update to the latest version of the application.