CVE-2020-7350
MEDIUMRapid7 Metasploit < 5.0.85 - OS Command Injection via libnotify Hostname or Service Name
Title source: llmExploitation Summary
EIP tracks 2 public exploits for CVE-2020-7350.
PoCs published by pastaoficial, pasta <[email protected]>, including Metasploit module exploits/unix/fileformat/metasploit_libnotify_cmd_injection.
AI-analyzed exploit summary The repository contains only a README with a title and an embedded video link, lacking any exploit code or technical details. No meaningful content or proof-of-concept is provided.
Description
Rapid7 Metasploit Framework versions before 5.0.85 suffers from an instance of CWE-78: OS Command Injection, wherein the libnotify plugin accepts untrusted user-supplied data via a remote computer's hostname or service name. An attacker can create a specially-crafted hostname or service name to be imported by Metasploit from a variety of sources and trigger a command injection on the operator's terminal. Note, only the Metasploit Framework and products that expose the plugin system is susceptible to this issue -- notably, this does not include Rapid7 Metasploit Pro. Also note, this vulnerability cannot be triggered through a normal scan operation -- the attacker would have to supply a file that is processed with the db_import command.
Exploits (2)
The repository contains only a README with a title and an embedded video link, lacking any exploit code or technical details. No meaningful content or proof-of-concept is provided.
This exploit leverages a command injection vulnerability in the Metasploit libnotify plugin by embedding malicious commands within an Nmap XML output file. The payload is executed when the file is processed by the vulnerable plugin.
References (1)
Scores
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:L/I:H/A:N