This is a detailed technical writeup describing a code execution vulnerability in Photo Manager Pro 4.4.0 iOS via the `folderName` parameter in the `newfolder.action` module. The vulnerability allows remote attackers to inject malicious code through crafted folder names, leading to session hijacking or persistent manipulation.
Classification
Writeup 90%
Target:
Photo Manager Pro 4.4.0 iOS
No auth needed
Prerequisites:
Network access to the vulnerable application · Ability to send crafted POST requests