Bulbsecurity develops a mobile penetration-testing framework whose vulnerabilities skew toward serious outcomes, with a notable tendency toward public exploit availability despite narrow product scope. The exposure recurs through input-handling and access-control weakness classes including OS command injection, cross-site request forgery, and SQL injection, which are characteristic of web-facing testing tools. Current severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Bulbsecurity over time
Signals from CVEs in this vendor scope (6 CVEs).
6 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2012-5878CRITICAL Bulb Security Smartphone Pentest Framework (SPF) 0.1.2 through 0.1.4 allows remote attackers to execute arbitrary commands via shell metacharacters in the hostingPath parameter to | Jan 3, 2020 | 9.8 | 47 | NO | YES |
CVE-2012-5693HIGH Bulb Security Smartphone Pentest Framework (SPF) before 0.1.3 allows remote attackers to execute arbitrary commands via shell metacharacters in the ipAddressTB parameter to (1) rem | Jan 3, 2020 | 8.8 | 27 | NO | NO |
CVE-2012-5695MEDIUM Multiple cross-site request forgery (CSRF) vulnerabilities in Bulb Security Smartphone Pentest Framework (SPF) 0.1.2 through 0.1.4 allow remote attackers to hijack the authenticati | Oct 20, 2014 | 6.8 | 22 | NO | NO |
CVE-2012-5694MEDIUM Multiple SQL injection vulnerabilities in Bulb Security Smartphone Pentest Framework (SPF) before 0.1.3 allow remote attackers to execute arbitrary SQL commands via the (1) agentPh | Oct 20, 2014 | 6.8 | 22 | NO | NO |
CVE-2012-5696MEDIUM Bulb Security Smartphone Pentest Framework (SPF) before 0.1.3 does not properly restrict access to frameworkgui/config, which allows remote attackers to obtain the plaintext databa | Oct 20, 2014 | 5.0 | 19 | NO | NO |
CVE-2012-5697MEDIUM The btinstall installation script in Bulb Security Smartphone Pentest Framework (SPF) before 0.1.3 uses weak permissions (777) for all files in the frameworkgui/ directory, which a | Oct 20, 2014 | 4.6 | 18 | NO | NO |
Signals from CVEs in this vendor scope (6 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Bulbsecurity.
Media articles that mention a CVE ID that affects a product developed by Bulbsecurity — matched by CVE ID, not by vendor name.