CVE-2012-5697
N/A
N/A
Summary
The btinstall installation script in Bulb Security Smartphone Pentest Framework (SPF) before 0.1.3 uses weak permissions (777) for all files in the frameworkgui/ directory, which allows local users to obtain sensitive information or inject arbitrary Perl code via direct access to these files.
Affected Software
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| n/a | n/a | n/a | affected |
Weaknesses
- n/a
ADP Enrichment
CVE Program Container
Additional References
- https://www.htbridge.com/advisory/HTB23123
- https://twitter.com/georgiaweidman/statuses/269138431567855618
- http://secunia.com/advisories/51415
References
- https://www.htbridge.com/advisory/HTB23123
- https://twitter.com/georgiaweidman/statuses/269138431567855618
- http://secunia.com/advisories/51415
Feedback
Was this page helpful?
Glad to hear it! Please tell us how we can improve.
Sorry to hear that. Please tell us how we can improve.