CVE-2008-7138 Information
Feb 14, 2021
cve
Description
The Manager in Eye-Fi 1.1.2 generates predictable snonce values based on the time of day which allows remote attackers to bypass authentication and upload arbitrary images by guessing the snonce.
Reference
http://osvdb.org/42719 http://secunia.com/advisories/29221 http://www.informit.com/articles/article.aspx?p=1177111&seqNum=2 http://www.securityfocus.com/archive/1/489045/100/0/threaded http://www.securityfocus.com/bid/28085
Share on: