CVE-2011-4696
03.03.2014, 16:55
Directory traversal vulnerability in Eye-Fi Helper before 3.4.23 allows man-in-the-middle attackers to create arbitrary files via a .. (dot dot) in the filesignature in a GetPhotoStatus request.
Vendor | Product | Version |
---|---|---|
eye | eye-fi_helper | 𝑥 ≤ 3.3.0 |
eye | eye-fi_helper | 2.0.3.0 |
eye | eye-fi_helper | 2.0.4.0 |
eye | eye-fi_helper | 2.5.1.0 |
eye | eye-fi_helper | 2.5.4.0 |
eye | eye-fi_helper | 2.5.5.0 |
eye | eye-fi_helper | 2.5.26.0 |
eye | eye-fi_helper | 2.5.27.0 |
eye | eye-fi_helper | 2.6.0.0 |
eye | eye-fi_helper | 2.6.9.0 |
eye | eye-fi_helper | 2.6.12.0 |
eye | eye-fi_helper | 3.1.2 |
eye | eye-fi_helper | 3.1.9 |
eye | eye-fi_helper | 3.2.2 |
𝑥
= Vulnerable software versions
References