cve/2015/CVE-2015-7888.md
2024-06-18 02:51:15 +02:00

840 B

CVE-2015-7888

Description

Directory traversal vulnerability in the WifiHs20UtilityService on the Samsung S6 Edge LRX22G.G925VVRU1AOE2 allows remote attackers to overwrite or create arbitrary files as the system-level user via a .. (dot dot) in the name of a file, compressed into a zipped file named cred.zip, and downloaded to /sdcard/Download.

POC

Reference

Github