Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

CVE-2017-16835

Quick assessment

Affected
n/a n/a
Exploitation
No confirmed in-the-wild exploitation; assess based on exposure
Recommended action
Check the vendor advisory and references for a fixed version. If immediate upgrade is impossible, restrict exposure and increase monitoring.

Photo,Video Locker-Calculator for Android是一款基于Android平台的加密应用程序。该程序能够加密管理图片、视频或锁定应用程序。 基于Android平台的Photo,Video Locker-Calculator应用程序12.0版本中存在信息泄露漏洞,该漏洞源于AndroidManifest.xml文件的android:allowBackup值为true。攻击者可借助‘adb backup '-f smart.calculator.gallerylock'’命令利

AI Predicted 5.3 Difficulty: Easy EPSS 0.59% · P47

Possible ATT&CK Techniques 1 AI

T1190 · Exploit Public-Facing Application
Get alerts for future matching vulnerabilities Log in to subscribe

I. Basic Information for CVE-2017-16835

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
N/A
Source: CVE Program / CVE List V5
Vulnerability Description
The "Photo,Video Locker-Calculator" application 12.0 for Android has android:allowBackup="true" in AndroidManifest.xml, which allows attackers to obtain sensitive cleartext information via an "adb backup '-f smart.calculator.gallerylock'" command.
Source: CVE Program / CVE List V5
CVSS Information
N/A
Source: CVE Program / CVE List V5
Vulnerability Type
N/A
Source: CVE Program / CVE List V5
Vulnerability Title
Photo,Video Locker-Calculator application for Android 信息泄露漏洞
Source: CNNVD (China National Vulnerability Database)
Vulnerability Description
Photo,Video Locker-Calculator for Android是一款基于Android平台的加密应用程序。该程序能够加密管理图片、视频或锁定应用程序。 基于Android平台的Photo,Video Locker-Calculator应用程序12.0版本中存在信息泄露漏洞,该漏洞源于AndroidManifest.xml文件的android:allowBackup值为true。攻击者可借助‘adb backup '-f smart.calculator.gallerylock'’命令利
Source: CNNVD (China National Vulnerability Database)
CVSS Information
N/A
Source: CNNVD (China National Vulnerability Database)
Vulnerability Type
N/A
Source: CNNVD (China National Vulnerability Database)

Affected Products

Vendor Product Affected Versions CPE Subscribe
- n/a n/a -

II. Public POCs for CVE-2017-16835

# POC Description Source Link Shenlong Link
AI-Generated POC Premium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2017-16835

登录查看更多情报信息。

Other References for CVE-2017-16835 (1)

Same Patch Batch · n/a · 2018-02-20 · 27 CVEs total

CVE-2017-16356 Kubik-Rubik SIGE 跨站脚本漏洞
CVE-2018-7259 Flight Sim Labs A320-X FSX / P3Dv4 installer 信息泄露漏洞
CVE-2017-18192 Photo,Video Locker-Calculator application for Android 信息泄露漏洞
CVE-2015-9256 Datto ALTO和SIRIS devices 信息泄露漏洞
CVE-2015-9255 Datto ALTO和SIRIS devices 信息泄露漏洞
CVE-2015-9254 Datto ALTO和SIRIS devices 安全漏洞
CVE-2015-2081 Datto ALTO和SIRIS devices 输入验证漏洞
CVE-2018-7205 Kentico 跨站脚本漏洞
CVE-2018-7046 Kentico 操作系统命令注入漏洞
CVE-2018-6941 NAT32 HTTPD组件跨站请求伪造漏洞
CVE-2018-6940 NAT32 HTTPD组件跨站脚本漏洞
CVE-2018-6459 strongSwan 安全漏洞
CVE-2018-6356 CloudBees Jenkins和Jenkins LTS 路径遍历漏洞
CVE-2017-12415 OXID eSales OXID eShop 跨站请求伪造漏洞
CVE-2016-6272 EPIC MyChart SQL注入漏洞
CVE-2017-6193 APNGDis 缓冲区错误漏洞
CVE-2017-6192 APNGDis 缓冲区错误漏洞
CVE-2018-5477 ABB netCADOPS Web Application 信息泄露漏洞
CVE-2017-10963 Samsung Knox SDS IAM和EMM 安全漏洞
CVE-2015-6544 Combodo iTop 跨站脚本漏洞

Showing top 20 of 27 CVEs. View all on vendor page → →

IV. Related Vulnerabilities

V. Comments for CVE-2017-16835

No comments yet


Leave a comment