RSS   Vulnerabilities for 'Mobiletrack'   RSS

2012-05-22
 
CVE-2012-2567

CWE-255
 

 
The Xelex MobileTrack application 2.3.7 and earlier for Android uses hardcoded credentials, which allows remote attackers to obtain sensitive information via an unencrypted (1) FTP or (2) HTTP session.

 
 
CVE-2012-2562

CWE-287
 

 
The Xelex MobileTrack application 2.3.7 and earlier for Android does not verify the origin of SMS commands, which allows remote attackers to execute a (1) LOCATE, (2) TRACK, (3) UPDATECFG, (4) UPDATEACCT, (5) STAT, (6) TERM, or (7) WIPE command via an SMS message.

 


Copyright 2024, cxsecurity.com

 

Back to Top