CVE-2013-5725

Severity CVSS v4.0:
Pending analysis
Type:
CWE-264 Permissions, Privileges, and Access Control
Publication date:
01/10/2013
Last modified:
08/10/2013

Description

The Metaclassy Byword app 2.x before 2.1 for iOS does not require confirmation of Replace file actions, which allows remote attackers to overwrite arbitrary files via the name and text parameters in a byword://replace URL.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:metaclassy:byword:2.0.0:*:*:*:*:*:*:*
cpe:2.3:a:metaclassy:byword:2.0.1:*:*:*:*:*:*:*
cpe:2.3:a:metaclassy:byword:2.0.2:*:*:*:*:*:*:*
cpe:2.3:a:metaclassy:byword:2.0.3:*:*:*:*:*:*:*


References to Advisories, Solutions, and Tools