OSVDB ID: 18495

Title: Metasploit Framework msfweb Defanged Mode Remote Bypass

Info

Disclosure

Jul 24, 2005

Discovery

Unknown

Dates

Exploit

Unknown

Solution

Unknown

Description

The msfweb component of the Metasploit Framework contains a flaw that allows a remote attacker to bypass "defanged mode" security restrictions. The issue is due to a logic error in the msfweb server, allowing a remote user to overwrite the internal "_Defanged" environment variable before the security check is performed.

Classification

Location: Remote / Network Access
Attack Type: Input Manipulation
Impact: Loss of Confidentiality, Loss of Integrity, Loss of Availability
Exploit: Exploit Unknown
Disclosure: OSVDB Verified

Solution

Upgrade to version 2.4-current or higher, as it has been reported to fix this vulnerability. An upgrade is required as there are no known workarounds.

Products

Metasploit

Framework

2.4

References

Credit

  • Dino Dai Zovi - Matasano Security


Direct URL: http://osvdb.org/18495