This is a vulnerability writeup describing a local file include vulnerability in Photorange v1.0 iOS mobile web-application. The vulnerability allows remote attackers to include local files via the `filename` parameter in the `add file` module.
Classification
Writeup 90%
Attack Type
Info Leak
Complexity
Trivial
Reliability
Theoretical
Target:Photorange iOS Mobile Web Application 1.0
No auth needed
Prerequisites:Network access to the vulnerable application · Ability to send crafted POST requests to the sync endpoint