The Manager in Eye-Fi 1.1.2 generates predictable snonce values based on the time of day, which allows remote attackers to bypass authentication and upload arbitrary images by guessing the snonce.
References
Configurations
History
No history.
Information
Published : 2009-09-01 16:30
Updated : 2024-02-28 11:21
NVD link : CVE-2008-7138
Mitre link : CVE-2008-7138
CVE.ORG link : CVE-2008-7138
JSON object : View
Products Affected
eye.fi
- eye-fi_manager
CWE
CWE-310
Cryptographic Issues