The Manager in Eye-Fi 1.1.2 generates predictable snonce values based on the time of day, which allows remote attackers to bypass authentication and upload arbitrary images by guessing the snonce.
References
Configurations
Information
Published : 2009-09-01 09:30
Updated : 2018-10-11 13:58
NVD link : CVE-2008-7138
Mitre link : CVE-2008-7138
JSON object : View
CWE
CWE-310
Cryptographic Issues
Products Affected
eye.fi
- eye-fi_manager