NetEase Personal Address Book for iOS Arbitrary File Upload Vulnerability
BID:62385
Info
NetEase Personal Address Book for iOS Arbitrary File Upload Vulnerability
| Bugtraq ID: | 62385 |
| Class: | Design Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Sep 12 2013 12:00AM |
| Updated: | Sep 12 2013 12:00AM |
| Credit: | Larry W. Cashdollar |
| Vulnerable: |
NetEase Personal Address Book 2.0 |
| Not Vulnerable: | |
Discussion
NetEase Personal Address Book for iOS Arbitrary File Upload Vulnerability
NetEase Personal Address Book for iOS is prone to an arbitrary file-upload vulnerability because it fails to properly validate the request.
An attacker may leverage this issue to upload arbitrary files without requiring authentication in the context of the affected application. This may lead to further attacks.
NetEase lua Personal Address Book for iOS 2.0 is vulnerable; other versions may also be affected.
NetEase Personal Address Book for iOS is prone to an arbitrary file-upload vulnerability because it fails to properly validate the request.
An attacker may leverage this issue to upload arbitrary files without requiring authentication in the context of the affected application. This may lead to further attacks.
NetEase lua Personal Address Book for iOS 2.0 is vulnerable; other versions may also be affected.
Exploit / POC
NetEase Personal Address Book for iOS Arbitrary File Upload Vulnerability
An attacker can exploit this issue using a web browser.
An attacker can exploit this issue using a web browser.
Solution / Fix
NetEase Personal Address Book for iOS Arbitrary File Upload Vulnerability
Solution:
Currently, we are not aware of any vendor-supplied patches. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Solution:
Currently, we are not aware of any vendor-supplied patches. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
References
NetEase Personal Address Book for iOS Arbitrary File Upload Vulnerability
References:
References:
- NetEase Homepage (NetEase)
- Personal Address Book-helpful (NetEase)
- TITLE: Unauthenticated Remote File Upload via HTTP for Personal Address Book 2.0 (Larry W. Cashdollar)