Rapid7
Rapid7 Metasploit: vulnerabilidades y CVE
Rapid7 Metasploit tiene 17 vulnerabilidades publicadas, 0 de ellas en los últimos 12 meses. 1 son críticas y 0 figuran en el catálogo de explotación activa de CISA.
CVE17
Últimos 12 meses0
Críticas1
Explotadas activamente0
Todas las vulnerabilidades en el catálogo →⭐ Seguir esta tecnología
Últimas vulnerabilidades
| CVE | Severidad | EPSS | Explotación activa | Publicada | Descripción |
|---|---|---|---|---|---|
| CVE-2023-0599 | Media (4.8) | 0.37% | — | 1 feb 2023 | Rapid7 Metasploit Pro versions 4.21.2 and lower suffer from a stored cross site scripting vulnerability, due to a lack of JavaScript request string sanitization. Using this vulnerability, an authenticated attacker can… |
| CVE-2020-7385 | Alta (8.8) | 1.8% | — | 23 abr 2021 | By launching the drb_remote_codeexec exploit, a Metasploit Framework user will inadvertently expose Metasploit to the same deserialization issue that is exploited by that module, due to the reliance on the vulnerable… |
| CVE-2020-7384 | Alta (7.8) | 30% | — | 29 oct 2020 | Rapid7's Metasploit msfvenom framework handles APK files in a way that allows for a malicious user to craft and publish a file that would execute arbitrary commands on a victim's machine. |
| CVE-2019-5645 | Alta (7.5) | 42% | — | 1 sept 2020 | By sending a specially crafted HTTP GET request to a listening Rapid7 Metasploit HTTP handler, an attacker can register an arbitrary regular expression. When evaluated, this malicious handler can either prevent new HTTP… |
| CVE-2020-7377 | Alta (7.5) | 1.1% | — | 24 ago 2020 | The Metasploit Framework module "auxiliary/admin/http/telpho10_credential_dump" module is affected by a relative path traversal vulnerability in the untar method which can be exploited to write arbitrary files to… |
| CVE-2020-7376 | Crítica (9.8) | 1.1% | — | 24 ago 2020 | The Metasploit Framework module "post/osx/gather/enum_osx module" is affected by a relative path traversal vulnerability in the get_keychains method which can be exploited to write arbitrary files to arbitrary locations… |
| CVE-2020-7355 | Media (6.1) | 0.88% | — | 25 jun 2020 | Cross-site Scripting (XSS) vulnerability in the 'notes' field of a discovered scan asset in Rapid7 Metasploit Pro allows an attacker with a specially-crafted network service of a scan target store an XSS sequence in the… |
| CVE-2020-7354 | Media (5.4) | 0.88% | — | 25 jun 2020 | Cross-site Scripting (XSS) vulnerability in the 'host' field of a discovered scan asset in Rapid7 Metasploit Pro allows an attacker with a specially-crafted network service of a scan target to store an XSS sequence in… |
| CVE-2020-7350 | Alta (7.8) | 5.0% | — | 22 abr 2020 | Rapid7 Metasploit Framework versions before 5.0.85 suffers from an instance of CWE-78: OS Command Injection, wherein the libnotify plugin accepts untrusted user-supplied data via a remote computer's hostname or service… |
| CVE-2019-5642 | Baja (3.3) | 0.31% | — | 6 nov 2019 | Rapid7 Metasploit Pro version 4.16.0-2019081901 and prior suffers from an instance of CWE-732, wherein the unique server.key is written to the file system during installation with world-readable permissions. This can… |
| CVE-2019-5624 | Alta (7.3) | 2.8% | — | 30 abr 2019 | Rapid7 Metasploit Framework suffers from an instance of CWE-22, Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') in the Zip import function of Metasploit. Exploiting this vulnerability can… |
| CVE-2017-15084 | Media (6.5) | 1.5% | — | 6 oct 2017 | The web UI in Rapid7 Metasploit before 4.14.1-20170828 allows logout CSRF, aka R7-2017-22. |
| CVE-2017-5244 | Baja (3.5) | 0.72% | — | 15 jun 2017 | Routes used to stop running Metasploit tasks (either particular ones or all tasks) allowed GET requests. Only POST requests should have been allowed, as the stop/stop_all routes change the state of the service. This… |
| CVE-2017-5235 | Alta (7.8) | 0.91% | — | 2 mar 2017 | Rapid7 Metasploit Pro installers prior to version 4.13.0-2017022101 contain a DLL preloading vulnerability, wherein it is possible for the installer to load a malicious DLL located in the current working directory of… |
| CVE-2017-5231 | Alta (7.1) | 1.2% | — | 2 mar 2017 | All editions of Rapid7 Metasploit prior to version 4.13.0-2017020701 contain a directory traversal vulnerability in the Meterpreter stdapi CommandDispatcher.cmd_download() function. By using a specially-crafted build of… |
| CVE-2017-5229 | Alta (7.1) | 1.2% | — | 2 mar 2017 | All editions of Rapid7 Metasploit prior to version 4.13.0-2017020701 contain a directory traversal vulnerability in the Meterpreter extapi Clipboard.parse_dump() function. By using a specially-crafted build of… |
| CVE-2017-5228 | Alta (7.1) | 1.2% | — | 2 mar 2017 | All editions of Rapid7 Metasploit prior to version 4.13.0-2017020701 contain a directory traversal vulnerability in the Meterpreter stdapi Dir.download() function. By using a specially-crafted build of Meterpreter, it… |