PT-2014-2356 · Bulb Security · Bulb Security Smartphone Pentest Framework

Published

2014-10-20

·

Updated

2017-08-29

·

CVE-2012-5695

CVSS v2.0

6.8

Medium

VectorAV:N/AC:M/Au:N/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions Bulb Security Smartphone Pentest Framework (SPF) versions 0.1.2 through 0.1.4
Description The issue allows remote attackers to hijack the authentication of administrators for requests, potentially leading to shell metacharacter, SQL injection attacks, or sending an SMS message.
Recommendations For versions 0.1.2 through 0.1.4, update to a version that contains a fix for this issue to prevent remote attackers from hijacking administrator authentication.

Exploit

Fix

CSRF

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2012-5695

Affected Products

Bulb Security Smartphone Pentest Framework