This is a detailed vulnerability writeup describing a local file include vulnerability in AllReader v1.0 iOS application. The exploit involves tampering with the filename parameter during file upload to include malicious local file paths.
Classification
Writeup 90%
Attack Type
Info Leak
Complexity
Moderate
Reliability
Reliable
Target:AllReader v1.0 iOS
No auth needed
Prerequisites:Access to the same network as the target device · AllReader v1.0 iOS application installed and running with WiFi server enabled