Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
N/A
Vulnerability Description
Bulb Security Smartphone Pentest Framework (SPF) before 0.1.3 does not properly restrict access to frameworkgui/config, which allows remote attackers to obtain the plaintext database password via a direct request.
CVSS Information
N/A
Vulnerability Type
N/A
Vulnerability Title
Bulb Security Smartphone Pentest Framework 授权问题漏洞
Vulnerability Description
Bulb Security Smartphone Pentest Framework(SPF)是一套开源的智能手机渗透测试框架,它可帮助测试当前网络环境中手机的安全漏洞,包括远程漏洞、客户端漏洞和、本地提权等。 Bulb Security SPF 0.1.3之前版本中存在安全漏洞,该漏洞源于程序没有正确限制对frameworkgui/config URI的访问。远程攻击者可通过发送直接的请求利用该漏洞获取明文数据库密码。
CVSS Information
N/A
Vulnerability Type
N/A