CVE-2017-1002000
How to Create an App for Android iPhone Easytouch <= 3.0 - Missing Authorization
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
2Exploited in Wild
-Decision
Descriptions
Vulnerability in wordpress plugin mobile-friendly-app-builder-by-easytouch v3.0, The code in file ./mobile-friendly-app-builder-by-easytouch/server/images.php doesn't require authentication or check that the user is allowed to upload content.
Existe una vulnerabilidad en el plugin mobile-friendly-app-builder-by-easytouch v3.0 en WordPress. El código en el archivo ./mobile-friendly-app-builder-by-easytouch/server/images.php no requiere autenticación o no verifica que el usuario tenga permisos para subir contenido.
WordPress plugins Zen App Mobile Native versions 3.0 and below, webapp-builder version 2.0, wp2android-turn-wp-site-into-android-app version 1.1.4, mobile-app-builder-by-wappress version 1.05, and mobile-friendly-app-builder-by-easytouch version 3.0 suffer from a remote shell upload vulnerability.
CVSS Scores
SSVC
- Decision:-
Timeline
- 2017-03-01 CVE Published
- 2017-09-14 CVE Reserved
- 2023-12-19 EPSS Updated
- 2024-08-05 CVE Updated
- 2024-08-05 First Exploit
- ---------- Exploited in Wild
- ---------- KEV Due Date
CWE
- CWE-434: Unrestricted Upload of File with Dangerous Type
- CWE-862: Missing Authorization
CAPEC
References (5)
URL | Tag | Source |
---|---|---|
http://www.securityfocus.com/bid/96899 | Third Party Advisory | |
http://www.securityfocus.com/bid/96905 | Third Party Advisory | |
https://wordpress.org/plugins-wp/mobile-friendly-app-builder-by-easytouch | Not Applicable |
URL | Date | SRC |
---|---|---|
https://www.exploit-db.com/exploits/41540 | 2024-08-05 | |
http://www.vapidlabs.com/advisory.php?v=179 | 2024-08-05 |
URL | Date | SRC |
---|
URL | Date | SRC |
---|
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Mobile-friendly-app-builder-by-easytouch Project Search vendor "Mobile-friendly-app-builder-by-easytouch Project" | Mobile-friendly-app-builder-by-easytouch Search vendor "Mobile-friendly-app-builder-by-easytouch Project" for product "Mobile-friendly-app-builder-by-easytouch" | 3.0 Search vendor "Mobile-friendly-app-builder-by-easytouch Project" for product "Mobile-friendly-app-builder-by-easytouch" and version "3.0" | wordpress |
Affected
|