what you don't know can hurt you
Home Files News &[SERVICES_TAB]About Contact Add New

File Explorer (FX) For Android Path Traversal

File Explorer (FX) For Android Path Traversal
Posted Feb 6, 2014
Authored by Keith Makan

File Explorer (FX) for Android suffers from a path traversal vulnerability. version 2.3.0.10 is affected.

tags | exploit, file inclusion
SHA-256 | 75beb06492c1bfac918f41afcd575cbf682aab74a42496ff864096601db8e3da

File Explorer (FX) For Android Path Traversal

Change Mirror Download
*# Disclosure Date:* 31 Jan 2014
*# Author: *Keith Makan (http://blog.k3170makan.com)
*# Vendor or Software Link:*
https://play.google.com/store/apps/details?id=nextapp.fx&hl=en

*# Version:* 2.3.0.10
*# Tested on:* Android 3.2.1
*# Site : http://blog.k3170makan.com <http://blog.k3170makan.com>*
Description: File Explorer (FX) for Android Suffers from a Path Traversal
and android.permission.storage permission leakage vulnerability.

The nextapp.fx.FileProvider Content Provider URI does not require any
Read/Write permissions yet allows unauthorized applications to make use of
the android.permission.STORAGE permission by providing them with access to
the local filesystem.
Impact: Malicious Android applications with no Permissions are capable of
leaking the contents of a victims local file system.

An estimated 500,000 - 1,000,000 installs are currently affected.
Fix:
Enforce android.permission.STORAGE Read/Write permission for the affected
content provider.

PoC available at:
>
http://blog.k3170makan.com/2014/02/path-traversal-vulnerability-in-file.html#more

*Timeline:*
31 Jan 2014 - Original Disclosure
06 February 2014 - Advisory Publication
--
<Keith k3170makan <http://about.me/k3170makan> Makan/>


-------------
Proof of concept:

dz> run app.provider.read content://nextapp.fx.FileProvider/
Is a directory
dz> run app.provider.read content://nextapp.fx.FileProvider/../../../system/etc/hosts
127.0.0.1 localhost


Login or Register to add favorites

File Archive:

August 2024

  • Su
  • Mo
  • Tu
  • We
  • Th
  • Fr
  • Sa
  • 1
    Aug 1st
    15 Files
  • 2
    Aug 2nd
    22 Files
  • 3
    Aug 3rd
    0 Files
  • 4
    Aug 4th
    0 Files
  • 5
    Aug 5th
    15 Files
  • 6
    Aug 6th
    11 Files
  • 7
    Aug 7th
    43 Files
  • 8
    Aug 8th
    42 Files
  • 9
    Aug 9th
    36 Files
  • 10
    Aug 10th
    0 Files
  • 11
    Aug 11th
    0 Files
  • 12
    Aug 12th
    27 Files
  • 13
    Aug 13th
    18 Files
  • 14
    Aug 14th
    50 Files
  • 15
    Aug 15th
    33 Files
  • 16
    Aug 16th
    23 Files
  • 17
    Aug 17th
    0 Files
  • 18
    Aug 18th
    0 Files
  • 19
    Aug 19th
    43 Files
  • 20
    Aug 20th
    29 Files
  • 21
    Aug 21st
    42 Files
  • 22
    Aug 22nd
    26 Files
  • 23
    Aug 23rd
    25 Files
  • 24
    Aug 24th
    0 Files
  • 25
    Aug 25th
    0 Files
  • 26
    Aug 26th
    21 Files
  • 27
    Aug 27th
    28 Files
  • 28
    Aug 28th
    0 Files
  • 29
    Aug 29th
    0 Files
  • 30
    Aug 30th
    0 Files
  • 31
    Aug 31st
    0 Files

Top Authors In Last 30 Days

File Tags

Systems

packet storm

© 2024 Packet Storm. All rights reserved.

Services
Security Services
Hosting By
Rokasec
close