{"api_version":"1","generated_at":"2026-07-23T09:25:43+00:00","cve":"CVE-2012-5878","urls":{"html":"https://cve.report/CVE-2012-5878","api":"https://cve.report/api/cve/CVE-2012-5878.json","docs":"https://cve.report/api","cve_org":"https://www.cve.org/CVERecord?id=CVE-2012-5878","nvd":"https://nvd.nist.gov/vuln/detail/CVE-2012-5878"},"summary":{"title":"CVE-2012-5878","description":"Bulb Security Smartphone Pentest Framework (SPF) 0.1.2 through 0.1.4 allows remote attackers to execute arbitrary commands via shell metacharacters in the hostingPath parameter to (1) SEAttack.pl or (2) CSAttack.pl in frameworkgui/ or the (3) appURLPath parameter to frameworkgui/attachMobileModem.pl.","state":"PUBLIC","assigner":"cve@mitre.org","published_at":"2020-01-03 20:15:00","updated_at":"2020-01-15 17:06:00"},"problem_types":["CWE-78"],"metrics":[],"references":[{"url":"https://www.htbridge.com/advisory/HTB23123","name":"https://www.htbridge.com/advisory/HTB23123","refsource":"MISC","tags":["Not Applicable","Third Party Advisory"],"title":"File Not Found","mime":"text/html","httpstatus":"404","archivestatus":"403"},{"url":"https://www.htbridge.com/advisory/HTB23127","name":"https://www.htbridge.com/advisory/HTB23127","refsource":"MISC","tags":["Exploit","Third Party Advisory"],"title":"File Not Found","mime":"text/html","httpstatus":"404","archivestatus":"403"},{"url":"https://www.cve.org/CVERecord?id=CVE-2012-5878","name":"CVE Program record","refsource":"CVE.ORG","tags":["canonical"]},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2012-5878","name":"NVD vulnerability detail","refsource":"NVD","tags":["canonical","analysis"]}],"affected":[],"timeline":[],"solutions":[],"workarounds":[],"exploits":[],"credits":[],"nvd_cpes":[{"cve_year":"2012","cve_id":"5878","vulnerable":"1","versionEndIncluding":"0.1.4","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"bulbsecurity","cpe5":"smartphone_pentest_framework","cpe6":"*","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"}],"vendor_comments":[],"enrichments":{"kev":null,"epss":null,"legacy_qids":[]},"source_records":{"cve_program":{"CVE_data_meta":{"ASSIGNER":"cve@mitre.org","ID":"CVE-2012-5878","STATE":"PUBLIC"},"data_format":"MITRE","data_type":"CVE","data_version":"4.0","description":{"description_data":[{"lang":"eng","value":"Bulb Security Smartphone Pentest Framework (SPF) 0.1.2 through 0.1.4 allows remote attackers to execute arbitrary commands via shell metacharacters in the hostingPath parameter to (1) SEAttack.pl or (2) CSAttack.pl in frameworkgui/ or the (3) appURLPath parameter to frameworkgui/attachMobileModem.pl."}]},"problemtype":{"problemtype_data":[{"description":[{"lang":"eng","value":"n/a"}]}]},"affects":{"vendor":{"vendor_data":[{"product":{"product_data":[{"product_name":"n/a","version":{"version_data":[{"version_value":"n/a"}]}}]},"vendor_name":"n/a"}]}},"references":{"reference_data":[{"refsource":"MISC","name":"https://www.htbridge.com/advisory/HTB23123","url":"https://www.htbridge.com/advisory/HTB23123"},{"refsource":"MISC","name":"https://www.htbridge.com/advisory/HTB23127","url":"https://www.htbridge.com/advisory/HTB23127"}]}},"nvd":{"publishedDate":"2020-01-03 20:15:00","lastModifiedDate":"2020-01-15 17:06:00","problem_types":["CWE-78"],"metrics":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH","baseScore":9.8,"baseSeverity":"CRITICAL"},"exploitabilityScore":3.9,"impactScore":5.9},"baseMetricV2":{"cvssV2":{"version":"2.0","vectorString":"AV:N/AC:L/Au:N/C:C/I:C/A:C","accessVector":"NETWORK","accessComplexity":"LOW","authentication":"NONE","confidentialityImpact":"COMPLETE","integrityImpact":"COMPLETE","availabilityImpact":"COMPLETE","baseScore":10},"severity":"HIGH","exploitabilityScore":10,"impactScore":10,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":false}},"configurations":{"CVE_data_version":"4.0","nodes":[{"operator":"OR","children":[],"cpe_match":[{"vulnerable":true,"cpe23Uri":"cpe:2.3:a:bulbsecurity:smartphone_pentest_framework:*:*:*:*:*:*:*:*","versionStartIncluding":"0.1.2","versionEndIncluding":"0.1.4","cpe_name":[]}]}]}},"legacy_mitre":{"record":{"CveYear":"2012","CveId":"5878","Ordinal":"58936","Title":"CVE-2012-5878","CVE":"CVE-2012-5878","Year":"2012"},"notes":[{"CveYear":"2012","CveId":"5878","Ordinal":"1","NoteData":"Bulb Security Smartphone Pentest Framework (SPF) 0.1.2 through 0.1.4 allows remote attackers to execute arbitrary commands via shell metacharacters in the hostingPath parameter to (1) SEAttack.pl or (2) CSAttack.pl in frameworkgui/ or the (3) appURLPath parameter to frameworkgui/attachMobileModem.pl.","Type":"Description","Title":null},{"CveYear":"2012","CveId":"5878","Ordinal":"2","NoteData":"2020-01-03","Type":"Other","Title":"Published"},{"CveYear":"2012","CveId":"5878","Ordinal":"3","NoteData":"2020-01-03","Type":"Other","Title":"Modified"}]}}}