VULNERABILITY INTELLIGENCE
CVE-2012-5697
CVSS score4.6 MEDIUM
EPSS probability0.42%
CISA KEVNot currently listed
Published2014-10-20
Last modified2026-06-16
CVSS vectorAV:L/AC:L/Au:N/C:P/I:P/A:P
Description
The btinstall installation script in Bulb Security Smartphone Pentest Framework (SPF) before 0.1.3 uses weak permissions (777) for all files in the frameworkgui/ directory, which allows local users to obtain sensitive information or inject arbitrary Perl code via direct access to these files.
Primary references
- cve@mitre.org
- cve@mitre.org — Vendor Advisory
- cve@mitre.org — Exploit
- af854a3a-2127-422b-91ae-364da2661108
- af854a3a-2127-422b-91ae-364da2661108 — Vendor Advisory
- af854a3a-2127-422b-91ae-364da2661108 — Exploit