← Back to CVEs
CVE-2012-5878
CRITICAL9.8
Description
Bulb Security Smartphone Pentest Framework (SPF) 0.1.2 through 0.1.4 allows remote attackers to execute arbitrary commands via shell metacharacters in the hostingPath parameter to (1) SEAttack.pl or (2) CSAttack.pl in frameworkgui/ or the (3) appURLPath parameter to frameworkgui/attachMobileModem.pl.
CVE Details
CVSS v3.1 Score9.8
SeverityCRITICAL
CVSS VectorCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Attack VectorNETWORK
ComplexityLOW
Privileges RequiredNONE
User InteractionNONE
Published1/3/2020
Last Modified11/21/2024
Sourcenvd
Honeypot Sightings0
Affected Products
bulbsecurity:smartphone_pentest_framework
Weaknesses (CWE)
CWE-78
References
https://www.htbridge.com/advisory/HTB23123(cve@mitre.org)
https://www.htbridge.com/advisory/HTB23127(cve@mitre.org)
https://www.htbridge.com/advisory/HTB23123(af854a3a-2127-422b-91ae-364da2661108)
https://www.htbridge.com/advisory/HTB23127(af854a3a-2127-422b-91ae-364da2661108)
IOC Correlations
No correlations recorded
This product uses data from the NVD API but is not endorsed or certified by the NVD.