AirDroid before 1.0.7 beta uses a cleartext base64 format for data transfer that is documented as an "Encrypted Transmission" feature, which allows remote attackers to obtain sensitive information by sniffing the local wireless network, as demonstrated by the SMS message content sent to the sdctl/sms/send/single/ URI.
History

No history.

cve-icon MITRE Information

Status: PUBLISHED

Assigner: mitre

Published: 2022-10-03T16:15:23

Updated: 2022-10-03T16:15:23

Reserved: 2022-10-03T00:00:00


Link: CVE-2012-3887

JSON object: View

cve-icon NVD Information

Status : Analyzed

Published: 2012-07-26T22:55:01.887

Modified: 2012-07-27T04:00:00.000


Link: CVE-2012-3887

JSON object: View

cve-icon Redhat Information

No data.

CWE