ePhoto Transfer Multiple Security Vulnerabilities
BID:61351
Info
ePhoto Transfer Multiple Security Vulnerabilities
| Bugtraq ID: | 61351 |
| Class: | Input Validation Error |
| CVE: | |
| Remote: | Yes |
| Local: | Yes |
| Published: | Jul 17 2013 12:00AM |
| Updated: | Jul 17 2013 12:00AM |
| Credit: | Benjamin Kunz Mejri |
| Vulnerable: |
EasierMobile ePhoto Transfer 1.2.1 |
| Not Vulnerable: | |
Discussion
ePhoto Transfer Multiple Security Vulnerabilities
ePhoto Transfer is prone to multiple security vulnerabilities including:
A local command-injection vulnerability
A remote denial-of-service vulnerability
A cross-site scripting vulnerability
An attacker can exploit these issues to execute arbitrary commands in the context of a user running the affected application, cause denial of service conditions, or execute arbitrary script code in the browser of an unsuspecting user in the context of the affected site. This may help the attacker steal cookie-based authentication credentials. Successful attacks can compromise the affected application and possibly the underlying computer.
ePhoto Transfer 1.2.1 is vulnerable; other versions may also be affected.
ePhoto Transfer is prone to multiple security vulnerabilities including:
A local command-injection vulnerability
A remote denial-of-service vulnerability
A cross-site scripting vulnerability
An attacker can exploit these issues to execute arbitrary commands in the context of a user running the affected application, cause denial of service conditions, or execute arbitrary script code in the browser of an unsuspecting user in the context of the affected site. This may help the attacker steal cookie-based authentication credentials. Successful attacks can compromise the affected application and possibly the underlying computer.
ePhoto Transfer 1.2.1 is vulnerable; other versions may also be affected.
Exploit / POC
ePhoto Transfer Multiple Security Vulnerabilities
An attacker can exploit these issues using a web browser. To exploit cross-site-scripting issue, an attacker must enticing an unsuspecting user to follow a malicious URI.
The following example data is available:
An attacker can exploit these issues using a web browser. To exploit cross-site-scripting issue, an attacker must enticing an unsuspecting user to follow a malicious URI.
The following example data is available:
Solution / Fix
ePhoto Transfer Multiple Security Vulnerabilities
Solution:
Currently, we are not aware of any vendor-supplied patches. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Solution:
Currently, we are not aware of any vendor-supplied patches. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
References
ePhoto Transfer Multiple Security Vulnerabilities
References:
References:
- ePhoto Transfer Homepage (Easiermobile)
- ePhoto Transfer v1.2.1 iOS - Multiple Web Vulnerabilities (Vulnerability Lab)