Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-hpwr-f2vf-gx3j

Опубликовано: 01 мая 2022
Источник: github
Github: Не прошло ревью

Описание

The StateToOptions function in msfweb in Metasploit Framework 2.4 and earlier, when running with the -D option (defanged mode), allows attackers to modify temporary environment variables before the "_Defanged" environment option is checked when processing the Exploit command.

The StateToOptions function in msfweb in Metasploit Framework 2.4 and earlier, when running with the -D option (defanged mode), allows attackers to modify temporary environment variables before the "_Defanged" environment option is checked when processing the Exploit command.

EPSS

Процентиль: 65%
0.00488
Низкий

Связанные уязвимости

nvd
больше 20 лет назад

The StateToOptions function in msfweb in Metasploit Framework 2.4 and earlier, when running with the -D option (defanged mode), allows attackers to modify temporary environment variables before the "_Defanged" environment option is checked when processing the Exploit command.

EPSS

Процентиль: 65%
0.00488
Низкий