{"api_version":"1","generated_at":"2026-07-23T03:44:45+00:00","cve":"CVE-2012-5694","urls":{"html":"https://cve.report/CVE-2012-5694","api":"https://cve.report/api/cve/CVE-2012-5694.json","docs":"https://cve.report/api","cve_org":"https://www.cve.org/CVERecord?id=CVE-2012-5694","nvd":"https://nvd.nist.gov/vuln/detail/CVE-2012-5694"},"summary":{"title":"CVE-2012-5694","description":"Multiple SQL injection vulnerabilities in Bulb Security Smartphone Pentest Framework (SPF) before 0.1.3 allow remote attackers to execute arbitrary SQL commands via the (1) agentPhNo, (2) controlPhNo, (3) agentURLPath, (4) agentControlKey, or (5) platformDD1 parameter to frameworkgui/attach2Agents.pl; the (6) modemPhoneNo, (7) controlKey, or (8) appURLPath parameter to frameworkgui/attachMobileModem.pl; the agentsDD parameter to (9) escalatePrivileges.pl, (10) getContacts.pl, (11) getDatabase.pl, (12) sendSMS.pl, or (13) takePic.pl in frameworkgui/; or the modemNoDD parameter to (14) escalatePrivileges.pl, (15) getContacts.pl, (16) getDatabase.pl, (17) SEAttack.pl, (18) sendSMS.pl, (19) takePic.pl, or (20) CSAttack.pl in frameworkgui/.","state":"PUBLISHED","assigner":"mitre","published_at":"2014-10-20 16:55:05","updated_at":"2026-05-06 22:30:45"},"problem_types":["CWE-89","n/a"],"metrics":[{"version":"2.0","source":"nvd@nist.gov","type":"Primary","score":"6.8","severity":"","vector":"AV:N/AC:M/Au:N/C:P/I:P/A:P","data":{"version":"2.0","vectorString":"AV:N/AC:M/Au:N/C:P/I:P/A:P","baseScore":6.8,"accessVector":"NETWORK","accessComplexity":"MEDIUM","authentication":"NONE","confidentialityImpact":"PARTIAL","integrityImpact":"PARTIAL","availabilityImpact":"PARTIAL"}}],"references":[{"url":"http://osvdb.org/87324","name":"http://osvdb.org/87324","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"","mime":"","httpstatus":"-1","archivestatus":"0"},{"url":"http://osvdb.org/87325","name":"http://osvdb.org/87325","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"","mime":"","httpstatus":"-1","archivestatus":"0"},{"url":"https://twitter.com/georgiaweidman/statuses/269138431567855618","name":"https://twitter.com/georgiaweidman/statuses/269138431567855618","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Vendor Advisory"],"title":"Georgia Weidman on Twitter: \"SPF GUI back in may god and infosec forgive me: https://t.co/ufeMXnmb\"","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://www.htbridge.com/advisory/HTB23123","name":"https://www.htbridge.com/advisory/HTB23123","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Exploit"],"title":"File Not Found","mime":"text/html","httpstatus":"404","archivestatus":"403"},{"url":"http://secunia.com/advisories/51414","name":"http://secunia.com/advisories/51414","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"Security Advisory SA51414 - Smartphone Pentest Framework frameworkgui Multiple Vulnerabilities - Secunia","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://www.cve.org/CVERecord?id=CVE-2012-5694","name":"CVE Program record","refsource":"CVE.ORG","tags":["canonical"]},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2012-5694","name":"NVD vulnerability detail","refsource":"NVD","tags":["canonical","analysis"]}],"affected":[{"source":"CNA","vendor":"n/a","product":"n/a","version":"affected n/a","platforms":[]}],"timeline":[],"solutions":[],"workarounds":[],"exploits":[],"credits":[],"nvd_cpes":[{"cve_year":"2012","cve_id":"5694","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"bulbsecurity","cpe5":"smartphone_pentest_framework","cpe6":"0.1.2","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"}],"vendor_comments":[],"enrichments":{"kev":null,"epss":null,"legacy_qids":[]},"source_records":{"cve_program":{"containers":{"adp":[{"providerMetadata":{"dateUpdated":"2024-08-06T21:14:16.351Z","orgId":"af854a3a-2127-422b-91ae-364da2661108","shortName":"CVE"},"references":[{"name":"87325","tags":["vdb-entry","x_refsource_OSVDB","x_transferred"],"url":"http://osvdb.org/87325"},{"name":"51414","tags":["third-party-advisory","x_refsource_SECUNIA","x_transferred"],"url":"http://secunia.com/advisories/51414"},{"tags":["x_refsource_MISC","x_transferred"],"url":"https://www.htbridge.com/advisory/HTB23123"},{"name":"87324","tags":["vdb-entry","x_refsource_OSVDB","x_transferred"],"url":"http://osvdb.org/87324"},{"tags":["x_refsource_MISC","x_transferred"],"url":"https://twitter.com/georgiaweidman/statuses/269138431567855618"}],"title":"CVE Program Container"}],"cna":{"affected":[{"product":"n/a","vendor":"n/a","versions":[{"status":"affected","version":"n/a"}]}],"datePublic":"2012-11-14T00:00:00.000Z","descriptions":[{"lang":"en","value":"Multiple SQL injection vulnerabilities in Bulb Security Smartphone Pentest Framework (SPF) before 0.1.3 allow remote attackers to execute arbitrary SQL commands via the (1) agentPhNo, (2) controlPhNo, (3) agentURLPath, (4) agentControlKey, or (5) platformDD1 parameter to frameworkgui/attach2Agents.pl; the (6) modemPhoneNo, (7) controlKey, or (8) appURLPath parameter to frameworkgui/attachMobileModem.pl; the agentsDD parameter to (9) escalatePrivileges.pl, (10) getContacts.pl, (11) getDatabase.pl, (12) sendSMS.pl, or (13) takePic.pl in frameworkgui/; or the modemNoDD parameter to (14) escalatePrivileges.pl, (15) getContacts.pl, (16) getDatabase.pl, (17) SEAttack.pl, (18) sendSMS.pl, (19) takePic.pl, or (20) CSAttack.pl in frameworkgui/."}],"problemTypes":[{"descriptions":[{"description":"n/a","lang":"en","type":"text"}]}],"providerMetadata":{"dateUpdated":"2014-10-20T15:57:00.000Z","orgId":"8254265b-2729-46b6-b9e3-3dfca2d5bfca","shortName":"mitre"},"references":[{"name":"87325","tags":["vdb-entry","x_refsource_OSVDB"],"url":"http://osvdb.org/87325"},{"name":"51414","tags":["third-party-advisory","x_refsource_SECUNIA"],"url":"http://secunia.com/advisories/51414"},{"tags":["x_refsource_MISC"],"url":"https://www.htbridge.com/advisory/HTB23123"},{"name":"87324","tags":["vdb-entry","x_refsource_OSVDB"],"url":"http://osvdb.org/87324"},{"tags":["x_refsource_MISC"],"url":"https://twitter.com/georgiaweidman/statuses/269138431567855618"}],"x_legacyV4Record":{"CVE_data_meta":{"ASSIGNER":"cve@mitre.org","ID":"CVE-2012-5694","STATE":"PUBLIC"},"affects":{"vendor":{"vendor_data":[{"product":{"product_data":[{"product_name":"n/a","version":{"version_data":[{"version_value":"n/a"}]}}]},"vendor_name":"n/a"}]}},"data_format":"MITRE","data_type":"CVE","data_version":"4.0","description":{"description_data":[{"lang":"eng","value":"Multiple SQL injection vulnerabilities in Bulb Security Smartphone Pentest Framework (SPF) before 0.1.3 allow remote attackers to execute arbitrary SQL commands via the (1) agentPhNo, (2) controlPhNo, (3) agentURLPath, (4) agentControlKey, or (5) platformDD1 parameter to frameworkgui/attach2Agents.pl; the (6) modemPhoneNo, (7) controlKey, or (8) appURLPath parameter to frameworkgui/attachMobileModem.pl; the agentsDD parameter to (9) escalatePrivileges.pl, (10) getContacts.pl, (11) getDatabase.pl, (12) sendSMS.pl, or (13) takePic.pl in frameworkgui/; or the modemNoDD parameter to (14) escalatePrivileges.pl, (15) getContacts.pl, (16) getDatabase.pl, (17) SEAttack.pl, (18) sendSMS.pl, (19) takePic.pl, or (20) CSAttack.pl in frameworkgui/."}]},"problemtype":{"problemtype_data":[{"description":[{"lang":"eng","value":"n/a"}]}]},"references":{"reference_data":[{"name":"87325","refsource":"OSVDB","url":"http://osvdb.org/87325"},{"name":"51414","refsource":"SECUNIA","url":"http://secunia.com/advisories/51414"},{"name":"https://www.htbridge.com/advisory/HTB23123","refsource":"MISC","url":"https://www.htbridge.com/advisory/HTB23123"},{"name":"87324","refsource":"OSVDB","url":"http://osvdb.org/87324"},{"name":"https://twitter.com/georgiaweidman/statuses/269138431567855618","refsource":"MISC","url":"https://twitter.com/georgiaweidman/statuses/269138431567855618"}]}}}},"cveMetadata":{"assignerOrgId":"8254265b-2729-46b6-b9e3-3dfca2d5bfca","assignerShortName":"mitre","cveId":"CVE-2012-5694","datePublished":"2014-10-20T16:00:00.000Z","dateReserved":"2012-10-29T00:00:00.000Z","dateUpdated":"2024-08-06T21:14:16.351Z","state":"PUBLISHED"},"dataType":"CVE_RECORD","dataVersion":"5.1"},"nvd":{"publishedDate":"2014-10-20 16:55:05","lastModifiedDate":"2026-05-06 22:30:45","problem_types":["CWE-89","n/a"],"metrics":{"cvssMetricV2":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"2.0","vectorString":"AV:N/AC:M/Au:N/C:P/I:P/A:P","baseScore":6.8,"accessVector":"NETWORK","accessComplexity":"MEDIUM","authentication":"NONE","confidentialityImpact":"PARTIAL","integrityImpact":"PARTIAL","availabilityImpact":"PARTIAL"},"baseSeverity":"MEDIUM","exploitabilityScore":8.6,"impactScore":6.4,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":false}]},"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:bulbsecurity:smartphone_pentest_framework:0.1.2:*:*:*:*:*:*:*","matchCriteriaId":"FCE8CA0E-060D-42A2-80BE-C909AAF76DA4"}]}]}]},"legacy_mitre":{"record":{"CveYear":"2012","CveId":"5694","Ordinal":"1","Title":"CVE-2012-5694","CVE":"CVE-2012-5694","Year":"2012"},"notes":[{"CveYear":"2012","CveId":"5694","Ordinal":"1","NoteData":"Multiple SQL injection vulnerabilities in Bulb Security Smartphone Pentest Framework (SPF) before 0.1.3 allow remote attackers to execute arbitrary SQL commands via the (1) agentPhNo, (2) controlPhNo, (3) agentURLPath, (4) agentControlKey, or (5) platformDD1 parameter to frameworkgui/attach2Agents.pl; the (6) modemPhoneNo, (7) controlKey, or (8) appURLPath parameter to frameworkgui/attachMobileModem.pl; the agentsDD parameter to (9) escalatePrivileges.pl, (10) getContacts.pl, (11) getDatabase.pl, (12) sendSMS.pl, or (13) takePic.pl in frameworkgui/; or the modemNoDD parameter to (14) escalatePrivileges.pl, (15) getContacts.pl, (16) getDatabase.pl, (17) SEAttack.pl, (18) sendSMS.pl, (19) takePic.pl, or (20) CSAttack.pl in frameworkgui/.","Type":"Description","Title":"CVE-2012-5694"},{"CveYear":"2012","CveId":"5694","Ordinal":"2","NoteData":"2014-10-20","Type":"Other","Title":"Published"},{"CveYear":"2012","CveId":"5694","Ordinal":"3","NoteData":"2014-10-20","Type":"Other","Title":"Modified"}]}}}