Multiple vulnerabilities in Smartphone Pentest Framework

Posted: December 11, 2012 in Vulnerabilities
Tags: ,


Smartphone Pentest Framework

Vulnerability: Multiple vulnerabilities in Smartphone Pentest Framework (SPF)

Danger: Middle
Number of vulnerabilities: 1

CVE ID: CVE-2012-5878
Vector operation: LAN
Impact: System Compromise

Exploit: PoC code
Affected Products: Smartphone Pentest Framework (SPF) 1.x

Affected versions: Smartphone Pentest Framework (SPF) versions 0.1.3 and 0.1.4


Which can be exploited by malicious people to execute arbitrary commands on the system.

An unspecified input validation error in the parameter “hostingPath” in scripts and, the parameter “appURLPath” in script, and parameter “ipAddressTB” in script This can be exploited to execute arbitrary commands on the system.

Manufacturer URL:

We recommend our readers to stop using Smartphone Pentest Framework and run it in a sandbox.


Leave a Reply

Fill in your details below or click an icon to log in: Logo

You are commenting using your account. Log Out /  Change )

Twitter picture

You are commenting using your Twitter account. Log Out /  Change )

Facebook photo

You are commenting using your Facebook account. Log Out /  Change )

Connecting to %s