Document Title:
===============
PhotoSync Wifi & Bluetooth v1.0 - File Include Vulnerability
References (Source):
====================
http://www.vulnerability-lab.com/get_content.php?id=1289
Release Date:
=============
2014-08-04
Vulnerability Laboratory ID (VL-ID):
====================================
1289
Common Vulnerability Scoring System:
====================================
6.8
Product & Service Introduction:
===============================
PhotosSync - Wifi Bluetooth let you transfer photos from one iPhone, iPod Touch, iPad to another iPhone, iPod Touch, iPad, Mac and PC.
- Wifi Transfer, support PhotosSync or most web browsers(safari, firefox, chrome, opera, IE)
- Bluetooth Transfer, very useful when no wifi , no network available
- Upload photos from Mac/PC to iPhone, iPad, iPod Touch (Wifi needed)
- QRCode, scan QRCode to download photo, very convenient
( Copy of the Homepage: https://itunes.apple.com/ke/app/photossync-wifi-bluetooth/id570672848 )
Abstract Advisory Information:
==============================
The Vulnerability Laboratory Research Team discovered a local file include web vulnerability in the official PhotoSync Wifi&Bluetooth 1.0 iOS mobile application.
Vulnerability Disclosure Timeline:
==================================
2014-08-04: Public Disclosure (Vulnerability Laboratory)
Discovery Status:
=================
Published
Affected Product(s):
====================
Haixia Liu
Product: PhotoSync Wifi&Bluetooth - iOS Mobile Web Application 1.0
Exploitation Technique:
=======================
Local
Severity Level:
===============
High
Technical Details & Description:
================================
A local file include web vulnerability has been discovered in the official PhotoSync Wifi&Bluetooth 1.0 iOS mobile application.
The local file include web vulnerability allows remote attackers to unauthorized include local file/path requests or system specific
path commands to compromise the mobile web-application.
The web vulnerability is located in the `filename` value of the `upload` module. Remote attackers are able to inject own files with
malicious `filename` values in the `upload` POST method request to compromise the mobile web-application. The local file/path include
execution occcurs in the index `file list` context next to the vulnerable `filename` item value. The attacker is able to inject the
local malicious file request by usage of the available `wifi interface` (http://localhost:8000/) upload form.
Remote attackers are also able to exploit the filename validation issue in combination with persistent injected script codes to execute
different local malicious attacks requests. The attack vector is on the application-side of the wifi service and the request method to
inject is POST.
The security risk of the local file include web vulnerability is estimated as high with a cvss (common vulnerability scoring system) count
of 6.8. Exploitation of the local file include web vulnerability requires no privileged web-application user account or user interaction.
Successful exploitation of the local file include web vulnerability results in mobile application or connected device component compromise.
Request Method(s):
[+] [POST]
Vulnerable Service(s):
[+] PhotoSync Wifi&Bluetooth 1.0
Vulnerable Module(s):
[+] upload
Vulnerable Parameter(s):
[+] filename
Affected Module(s):
[+] PhotoSync Images Dir Listing (http://localhost:8000/)
Proof of Concept (PoC):
=======================
The local file include web vulnerability can be exploited by local attackers without privileged application user account and
without user interaction. For security demonstration or to reproduce follow the provided information and steps below to continue.
PoC:
http://localhost:8000/images/./[LOCAL FILE INCLUDE VULNERABILITY!]
PoC: Index File Dir Listing (http://localhost:8000/)
Deselect All
Select All
Save