Release date:
Updated on: 2013-02-23
Affected Systems:
Apple Air Disk Wireless HTTP File Sharing Application 1.9
Description:
--------------------------------------------------------------------------------
Bugtraq id: 57859
Air Disk Free is a wireless HTTP file sharing software.
The index module of the Air Disk Wireless HTTP File Sharing Application does not properly verify certain input, allowing remote attackers to inject and execute arbitrary commands on the system through device name parameters.
<* Source: Benjamin Kunz Mejri
Link: http://seclists.org/fulldisclosure/2013/Feb/28
Http://xforce.iss.net/xforce/xfdb/81958
*>
Suggestion:
--------------------------------------------------------------------------------
Vendor patch:
Apple
-----
Currently, the vendor does not provide patches or upgrade programs. We recommend that users who use the software follow the vendor's homepage to obtain the latest version:
Https://itunes.apple.com/us/app/air-disk-free-wireless-http/id444063740