CyberRota
Live Feed
Return to register
Case File

CVE-2012-5693

HIGH · CVSS 8.8 EPSS 1.66%

Source: NVD + CISA KEV + EPSS (historical backfill) · Published 2020-01-03 · Last synced 2026-08-04

Field Assessment

AI analysis pending.

CVE
CVE-2012-5693
Severity
HIGH
CVSS
8.8
EPSS
1.66%

Original Filing — NVD Description

Bulb Security Smartphone Pentest Framework (SPF) before 0.1.3 allows remote attackers to execute arbitrary commands via shell metacharacters in the ipAddressTB parameter to (1) remoteAttack.pl or (2) guessPassword.pl in frameworkgui/; the filename parameter to (3) CSAttack.pl or (4) SEAttack.pl in frameworkgui/; the phNo2Attack parameter to (5) CSAttack.pl or (6) SEAttack.pl in frameworkgui/; the (7) platformDD2 parameter to frameworkgui/SEAttack.pl; the (8) agentURLPath or (9) agentControlKey parameter to frameworkgui/attach2agents.pl; or the (10) controlKey parameter to frameworkgui/attachMobileModem.pl. NOTE: The hostingPath parameter to CSAttack.pl and SEAttack.pl vectors and the appURLPath parameter to attachMobileModem.pl vector are covered by CVE-2012-5878.