Showing 4 vulnerabilities on this page for Metasploit

Signals CISA KEV Ransomware Nuclei
Rapid7 vulnerability results
VulnerabilityTitle and contextCVSSEPSSPoCsSignalsSTIX action

Client-Side Command Injection in Rapid7 Metasploit

Rapid7's Metasploit msfvenom framework handles APK files in a way that allows for a malicious user to craft and publish a file that would execute arbitrary commands on a victim's machine.

CWE-77Oct 29, 2020
CVSS7.0v3.1EPSS30.5%PoCs4SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templatesSTIX

All editions of Rapid7 Metasploit prior to version 4.13.0-2017020701 contain a directory traversal vulnerability in the Meterpreter stdapi CommandDispatcher.cmd_download() function. By using a specially-crafted build of Meterpreter, it is possible to write to an arbitrary directory on the Metasploit console with the permissions of the running Metasploit instance.

CWE-22Mar 2, 2017
CVSS7.1v3.0EPSS1.22%PoCs0SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templatesSTIX

All editions of Rapid7 Metasploit prior to version 4.13.0-2017020701 contain a directory traversal vulnerability in the Meterpreter extapi Clipboard.parse_dump() function. By using a specially-crafted build of Meterpreter, it is possible to write to an arbitrary directory on the Metasploit console with the permissions of the running Metasploit instance.

CWE-22Mar 2, 2017
CVSS7.1v3.0EPSS1.22%PoCs0SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templatesSTIX

All editions of Rapid7 Metasploit prior to version 4.13.0-2017020701 contain a directory traversal vulnerability in the Meterpreter stdapi Dir.download() function. By using a specially-crafted build of Meterpreter, it is possible to write to an arbitrary directory on the Metasploit console with the permissions of the running Metasploit instance.

CWE-22Mar 2, 2017
CVSS7.1v3.0EPSS1.22%PoCs0SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templatesSTIX