Description
Mini Mouse 9.2.0 contains a path traversal vulnerability that allows remote attackers to access arbitrary system files and directories through crafted HTTP requests. Attackers can retrieve sensitive files like win.ini and list contents of system directories such as C:\Users\Public by manipulating file and path parameters.
Problem types
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')
Product status
Credits
gosh
References
www.exploit-db.com/exploits/49744 (ExploitDB-49744)
apps.apple.com/us/app/mini-mouse-remote-control/id914250948 (Mini Mouse Apple Store)
www.vulncheck.com/advisories/mini-mouse-path-traversal (VulnCheck Advisory: Mini Mouse 9.2.0 - Path Traversal)