Simple Transfer Local Command Injection Vulnerabilities
BID:59817
Info
Simple Transfer Local Command Injection Vulnerabilities
| Bugtraq ID: | 59817 |
| Class: | Input Validation Error |
| CVE: | |
| Remote: | No |
| Local: | Yes |
| Published: | May 12 2013 12:00AM |
| Updated: | May 12 2013 12:00AM |
| Credit: | Benjamin Kunz Mejri |
| Vulnerable: |
von Rambax Simple Transfer 2.2.1 for iPhone von Rambax Simple Transfer 2.2.1 for iPad |
| Not Vulnerable: | |
Discussion
Simple Transfer Local Command Injection Vulnerabilities
Simple Transfer is prone to multiple local command-injection vulnerabilities.
A local attacker can exploit these issues to execute arbitrary commands within the context of the affected application. Successful exploits may compromise the affected application.
The following versions are affected:
Simple Transfer 2.2.1 for iPad
Simple Transfer 2.2.1 for iPhone
Simple Transfer is prone to multiple local command-injection vulnerabilities.
A local attacker can exploit these issues to execute arbitrary commands within the context of the affected application. Successful exploits may compromise the affected application.
The following versions are affected:
Simple Transfer 2.2.1 for iPad
Simple Transfer 2.2.1 for iPhone
Exploit / POC
Simple Transfer Local Command Injection Vulnerabilities
The following proof of concept is available:
The following proof of concept is available:
References
Simple Transfer Local Command Injection Vulnerabilities
References:
References:
- Simple Transfer Product Page (von Rambax)
- SimpleTransfer 2.2.1 - Command Injection Vulnerabilities (Benjamin Kunz Mejri)