1000
VMScore

CVE-2012-5878

Published: 03/01/2020 Updated: 15/01/2020
CVSS v2 Base Score: 10 | Impact Score: 10 | Exploitability Score: 10
CVSS v3 Base Score: 9.8 | Impact Score: 5.9 | Exploitability Score: 3.9
VMScore: 1000
Vector: AV:N/AC:L/Au:N/C:C/I:C/A:C

Vulnerability Summary

Bulb Security Smartphone Pentest Framework (SPF) 0.1.2 up to and including 0.1.4 allows remote malicious users to execute arbitrary commands via shell metacharacters in the hostingPath parameter to (1) SEAttack.pl or (2) CSAttack.pl in frameworkgui/ or the (3) appURLPath parameter to frameworkgui/attachMobileModem.pl.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

bulbsecurity smartphone pentest framework

Exploits

source: wwwsecurityfocuscom/bid/56881/info Smartphone Pentest Framework is prone to multiple remote command-execution vulnerabilities Remote attackers can exploit these issues to execute arbitrary commands within the context of the vulnerable application to gain root access This may facilitate a complete compromise of an affected compu ...
Smartphone Pentest Framework (SPF) versions 013 and 014 suffer from an OS command injection vulnerability ...