Bulbsecurity
bulbsecurity
6 CVEs • 1 product
Products (1)
Click to collapseToggle
Products (1)
Click to collapse
CVEs (6)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
1Bulbsecurity 1Smartphone Pentest Framework Nov 21, 2024 Jan 3, 2020 N/A· v4 9.8 CRITICAL· v3 10.0 HIGH· v2 Bulb Security Smartphone Pentest Framework (SPF) 0.1.2 through 0.1.4 allows remote attackers to execute arbitrary commands via shell metacharacters in the hostingPath parameter to (1) SEAttack.pl or (2) CSAttack.pl in fr...Show more |
1Bulbsecurity 1Smartphone Pentest Framework Nov 21, 2024 Jan 3, 2020 N/A· v4 8.8 HIGH· v3 8.3 HIGH· v2 Bulb Security Smartphone Pentest Framework (SPF) before 0.1.3 allows remote attackers to execute arbitrary commands via shell metacharacters in the ipAddressTB parameter to (1) remoteAttack.pl or (2) guessPassword.pl in...Show more |
1Bulbsecurity 1Smartphone Pentest Framework May 6, 2026 Oct 20, 2014 N/A· v4 N/A· v3 4.6 MEDIUM· v2 The btinstall installation script in Bulb Security Smartphone Pentest Framework (SPF) before 0.1.3 uses weak permissions (777) for all files in the frameworkgui/ directory, which allows local users to obtain sensitive in...Show more |
1Bulbsecurity 1Smartphone Pentest Framework May 6, 2026 Oct 20, 2014 N/A· v4 N/A· v3 5.0 MEDIUM· v2 Bulb Security Smartphone Pentest Framework (SPF) before 0.1.3 does not properly restrict access to frameworkgui/config, which allows remote attackers to obtain the plaintext database password via a direct request. |
1Bulbsecurity 1Smartphone Pentest Framework May 6, 2026 Oct 20, 2014 N/A· v4 N/A· v3 6.8 MEDIUM· v2 Multiple cross-site request forgery (CSRF) vulnerabilities in Bulb Security Smartphone Pentest Framework (SPF) 0.1.2 through 0.1.4 allow remote attackers to hijack the authentication of administrators for requests that c...Show more |
1Bulbsecurity 1Smartphone Pentest Framework May 6, 2026 Oct 20, 2014 N/A· v4 N/A· v3 6.8 MEDIUM· v2 Multiple SQL injection vulnerabilities in Bulb Security Smartphone Pentest Framework (SPF) before 0.1.3 allow remote attackers to execute arbitrary SQL commands via the (1) agentPhNo, (2) controlPhNo, (3) agentURLPath, (...Show more |