Vulnerable Systems:
* WirelessFiles for iPad/iPhone 1.1
WirelessFiles for iPad/iPhone contains a flaw that allows a remote user to execute arbitrary script code. This flaw exists because the program does not properly verify or sanitize user-uploaded files. By uploading a .php file with multiple file extensions (e.g. myfile.php.gif), the upload will bypass the sanity check restricting file uploads. Once uploaded, the remote system will place the file in a user-accessible path. Making a direct request to the uploaded file will allow the user to execute the script code with the privileges of the web server.
Proof of Concept:
1.1
The vulnerability can be exploited by remote attackers with low privileged application user account and without required user interaction.
For demonstration or reproduce ...
1.2
The vulnerability can be exploited by remote attackers with low privileged application user account and without required user interaction.
For demonstration or reproduce ...