This is a vulnerability writeup describing a local command injection vulnerability in the WK UDID v1.0.1 iOS app. The vulnerability allows manipulation of the device name value to inject malicious script codes into the mail function.
Classification
Writeup 90%
Attack Type
Other
Complexity
Trivial
Reliability
Theoretical
Target:WK UDID - iOS Mobile Web Application 1.0.1
Auth required
Prerequisites:Local access to the iOS device · Ability to modify device name settings