bulbsecurity records
6 published records for vendor bulbsecurity.
Researcher profile
- Entered KEV
- 0 · 0%
- Weaponized
- 0 · 0%
- Pre-auth RCE
- 3
- With a fix record
- 0%
- Median publish → KEV
- No record has entered KEV
Recurring classes
- CWE-264 Permissions, Privileges, and Access Controls2
- CWE-78 Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')2
- CWE-352 Cross-Site Request Forgery (CSRF)1
- CWE-89 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')1
The weakness classes this vendor ships most often: where to look.
CWEAttack profile
All records
6 records| Action | CVE | Vulnerability | Severity | KEV | EPSS | Published |
|---|---|---|---|---|---|---|
42Plan | CVE-2012-5878Proof of concept | Bulb Security Smartphone Pentest Framework (SPF) 0.1.2 through 0.1.4 allows remote attackers to execute arbitrary commands via shell metachabulbsecurity · smartphone pentest framework · CWE-78 | Critical9.8 | — | 9.3% | Jan 3, 2020 |
35Monitor | CVE-2012-5693No exploit | Bulb Security Smartphone Pentest Framework (SPF) before 0.1.3 allows remote attackers to execute arbitrary commands via shell metacharactersbulbsecurity · smartphone pentest framework · CWE-78 | High8.8 | — | 1.7% | Jan 3, 2020 |
27Monitor | CVE-2012-5694No exploit | Multiple SQL injection vulnerabilities in Bulb Security Smartphone Pentest Framework (SPF) before 0.1.3 allow remote attackers to execute arbulbsecurity · smartphone pentest framework · CWE-89 | Medium6.8 | — | 1.3% | Oct 20, 2014 |
27Monitor | CVE-2012-5695No exploit | Multiple cross-site request forgery (CSRF) vulnerabilities in Bulb Security Smartphone Pentest Framework (SPF) 0.1.2 through 0.1.4 allow rembulbsecurity · smartphone pentest framework · CWE-352 | Medium6.8 | — | 0.7% | Oct 20, 2014 |
20Monitor | CVE-2012-5696No exploit | Bulb Security Smartphone Pentest Framework (SPF) before 0.1.3 does not properly restrict access to frameworkgui/config, which allows remote bulbsecurity · smartphone pentest framework · CWE-264 | Medium5.0 | — | 1.3% | Oct 20, 2014 |
18Monitor | CVE-2012-5697No exploit | The btinstall installation script in Bulb Security Smartphone Pentest Framework (SPF) before 0.1.3 uses weak permissions (777) for all filesbulbsecurity · smartphone pentest framework · CWE-264 | Medium4.6 | — | 0.4% | Oct 20, 2014 |
- CVE-2012-587842Plan
Bulb Security Smartphone Pentest Framework (SPF) 0.1.2 through 0.1.4 allows remote attackers to execute arbitrary commands via shell metacha
CriticalCVSS 9.8Proof of conceptEPSS 9%bulbsecurity · smartphone pentest frameworkJan 3, 2020
- CVE-2012-569335Monitor
Bulb Security Smartphone Pentest Framework (SPF) before 0.1.3 allows remote attackers to execute arbitrary commands via shell metacharacters
HighCVSS 8.8No exploitEPSS 2%bulbsecurity · smartphone pentest frameworkJan 3, 2020
- CVE-2012-569427Monitor
Multiple SQL injection vulnerabilities in Bulb Security Smartphone Pentest Framework (SPF) before 0.1.3 allow remote attackers to execute ar
MediumCVSS 6.8No exploitEPSS 1%bulbsecurity · smartphone pentest frameworkOct 20, 2014
- CVE-2012-569527Monitor
Multiple cross-site request forgery (CSRF) vulnerabilities in Bulb Security Smartphone Pentest Framework (SPF) 0.1.2 through 0.1.4 allow rem
MediumCVSS 6.8No exploitEPSS 1%bulbsecurity · smartphone pentest frameworkOct 20, 2014
- CVE-2012-569620Monitor
Bulb Security Smartphone Pentest Framework (SPF) before 0.1.3 does not properly restrict access to frameworkgui/config, which allows remote
MediumCVSS 5.0No exploitEPSS 1%bulbsecurity · smartphone pentest frameworkOct 20, 2014
- CVE-2012-569718Monitor
The btinstall installation script in Bulb Security Smartphone Pentest Framework (SPF) before 0.1.3 uses weak permissions (777) for all files
MediumCVSS 4.6No exploitEPSS 0%bulbsecurity · smartphone pentest frameworkOct 20, 2014