CVE-2012-5694

Bulb Security Smartphone Pentest Framework <0.1.3 - SQL Injection

Title source: llm
STIX 2.1

Description

Multiple SQL injection vulnerabilities in Bulb Security Smartphone Pentest Framework (SPF) before 0.1.3 allow remote attackers to execute arbitrary SQL commands via the (1) agentPhNo, (2) controlPhNo, (3) agentURLPath, (4) agentControlKey, or (5) platformDD1 parameter to frameworkgui/attach2Agents.pl; the (6) modemPhoneNo, (7) controlKey, or (8) appURLPath parameter to frameworkgui/attachMobileModem.pl; the agentsDD parameter to (9) escalatePrivileges.pl, (10) getContacts.pl, (11) getDatabase.pl, (12) sendSMS.pl, or (13) takePic.pl in frameworkgui/; or the modemNoDD parameter to (14) escalatePrivileges.pl, (15) getContacts.pl, (16) getDatabase.pl, (17) SEAttack.pl, (18) sendSMS.pl, (19) takePic.pl, or (20) CSAttack.pl in frameworkgui/.

References (5)

Core 5
Core References
Third Party Advisory, VDB Entry vdb-entry x_refsource_osvdb
http://osvdb.org/87325
Third Party Advisory third-party-advisory x_refsource_secunia
http://secunia.com/advisories/51414
Third Party Advisory, VDB Entry vdb-entry x_refsource_osvdb
http://osvdb.org/87324

Scores

EPSS 0.0127
EPSS Percentile 66.7%

Details

CWE
CWE-89
Status published
Products (1)
bulbsecurity/smartphone_pentest_framework 0.1.2
Published Oct 20, 2014
Tracked Since Feb 18, 2026