Vulnerabilities
Vulnerable Software
Metasploit:  >> Metasploit Framework  Security Vulnerabilities
The installer for Metasploit Framework 3.5.1, when running on Windows, uses weak inherited permissions for the Metasploit installation directory, which allows local users to gain privileges by replacing critical files with a Trojan horse.
CVSS Score
6.2
EPSS Score
0.0
Published
2011-02-21
The StateToOptions function in msfweb in Metasploit Framework 2.4 and earlier, when running with the -D option (defanged mode), allows attackers to modify temporary environment variables before the "_Defanged" environment option is checked when processing the Exploit command.
CVSS Score
5.0
EPSS Score
0.005
Published
2005-08-07


Contact Us

Shodan ® - All rights reserved