CVE-2017-16835

Severity CVSS v4.0:
Pending analysis
Type:
CWE-312 Cleartext Storage of Sensitive Information
Publication date:
20/02/2018
Last modified:
03/10/2019

Description

The "Photo,Video Locker-Calculator" application 12.0 for Android has android:allowBackup="true" in AndroidManifest.xml, which allows attackers to obtain sensitive cleartext information via an "adb backup '-f smart.calculator.gallerylock'" command.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:photo\,video_locker-calculator_project:photo\,video_locker-calculator:12.0:*:*:*:*:android:*:*