Smartphone Pentest Framework Multiple Security Vulnerabilities
BID:56705
Info
Smartphone Pentest Framework Multiple Security Vulnerabilities
| Bugtraq ID: | 56705 |
| Class: | Unknown |
| CVE: |
CVE-2012-5693 CVE-2012-5694 CVE-2012-5695 CVE-2012-5696 |
| Remote: | Yes |
| Local: | No |
| Published: | Nov 14 2012 12:00AM |
| Updated: | Nov 14 2012 12:00AM |
| Credit: | High-Tech Bridge and Jon Passki |
| Vulnerable: |
Bulb Security LLC Smartphone Pentest Framework 0.1.2 |
| Not Vulnerable: |
Bulb Security LLC Smartphone Pentest Framework 0.1.3 |
Discussion
Smartphone Pentest Framework Multiple Security Vulnerabilities
Smartphone Pentest Framework is prone to multiple security vulnerabilities, including:
1. Multiple command-injection vulnerabilities
2. Multiple SQL-injection vulnerabilities
3. A cross-site request-forgery vulnerability
4. A security bypass vulnerability
Attackers can exploit these issues to bypass certain security restrictions, obtain sensitive information, perform unauthorized actions, compromise the application, access or modify data, or exploit latent vulnerabilities in the underlying database.
Smartphone Pentest Framework 0.1.2 is vulnerable; other versions may also be affected.
Smartphone Pentest Framework is prone to multiple security vulnerabilities, including:
1. Multiple command-injection vulnerabilities
2. Multiple SQL-injection vulnerabilities
3. A cross-site request-forgery vulnerability
4. A security bypass vulnerability
Attackers can exploit these issues to bypass certain security restrictions, obtain sensitive information, perform unauthorized actions, compromise the application, access or modify data, or exploit latent vulnerabilities in the underlying database.
Smartphone Pentest Framework 0.1.2 is vulnerable; other versions may also be affected.
Exploit / POC
Smartphone Pentest Framework Multiple Security Vulnerabilities
An attacker may use a browser to exploit these issues. In some cases, the attacker may need to entice an unsuspecting victim into following a malicious URI.
An attacker may use a browser to exploit these issues. In some cases, the attacker may need to entice an unsuspecting victim into following a malicious URI.
Solution / Fix
Smartphone Pentest Framework Multiple Security Vulnerabilities
Solution:
Updates are available. Please see the references for more information.
Solution:
Updates are available. Please see the references for more information.
References
Smartphone Pentest Framework Multiple Security Vulnerabilities
References:
References:
- Multiple Vulnerabilities in Smartphone Pentest Framework (SPF) (High-Tech Bridge SA)
- Smartphone Pentest Framework Homepage (Bulb Security LLC)