5
CVSSv2

CVE-2013-5725

Published: 01/10/2013 Updated: 08/10/2013
CVSS v2 Base Score: 5 | Impact Score: 2.9 | Exploitability Score: 10
VMScore: 445
Vector: AV:N/AC:L/Au:N/C:N/I:P/A:N

Vulnerability Summary

The Metaclassy Byword app 2.x prior to 2.1 for iOS does not require confirmation of Replace file actions, which allows remote malicious users to overwrite arbitrary files via the name and text parameters in a byword://replace URL.

Vulnerable Product Search on Vulmon Subscribe to Product

metaclassy byword 2.0.1

metaclassy byword 2.0.2

metaclassy byword 2.0.3

metaclassy byword 2.0.0

Exploits

Byword versions prior to 21 allow for a remote file overwrite attack ...