Metasploit Framework MSFWeb Defanged Mode Restriction Bypass Vulnerability
BID:14455
Info
Metasploit Framework MSFWeb Defanged Mode Restriction Bypass Vulnerability
| Bugtraq ID: | 14455 |
| Class: | Access Validation Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Aug 02 2005 12:00AM |
| Updated: | Aug 02 2005 12:00AM |
| Credit: | Dino Dai Zovi reported this issue to the vendor. |
| Vulnerable: |
Metasploit Project Metasploit Framework 2.4 Metasploit Project Metasploit Framework 2.3 Metasploit Project Metasploit Framework 2.2 Metasploit Project Metasploit Framework 2.1 Metasploit Project Metasploit Framework 2.0 Metasploit Project Metasploit Framework 1.0 |
| Not Vulnerable: | |
Discussion
Metasploit Framework MSFWeb Defanged Mode Restriction Bypass Vulnerability
Metasploit Framework is susceptible to a restriction bypass vulnerability in msfweb. This issue is due to a failure of the application to properly implement access control restrictions.
This issue allows remote attackers to bypass security restrictions in the affected Web server. Attackers may exploit this issue to attack arbitrary computers using the Metasploit Framework, while originating the attacks from the computer hosting the vulnerable msfweb process.
Attackers may also interact with the payload features in the Metasploit Framework to manipulate files on the hosting computer, likely leading to executing arbitrary commands and then complete system compromise.
It should be noted that the Metasploit Framework documentation specifies that msfweb should not be globally accessible, due to potential security problems.
Metasploit Framework is susceptible to a restriction bypass vulnerability in msfweb. This issue is due to a failure of the application to properly implement access control restrictions.
This issue allows remote attackers to bypass security restrictions in the affected Web server. Attackers may exploit this issue to attack arbitrary computers using the Metasploit Framework, while originating the attacks from the computer hosting the vulnerable msfweb process.
Attackers may also interact with the payload features in the Metasploit Framework to manipulate files on the hosting computer, likely leading to executing arbitrary commands and then complete system compromise.
It should be noted that the Metasploit Framework documentation specifies that msfweb should not be globally accessible, due to potential security problems.
Exploit / POC
Metasploit Framework MSFWeb Defanged Mode Restriction Bypass Vulnerability
An exploit is not required.
An exploit is not required.
Solution / Fix
Metasploit Framework MSFWeb Defanged Mode Restriction Bypass Vulnerability
Solution:
The vendor has created patches to address this issue. Users of affected packages should contact the vendor for further information on obtaining fixes.
Solution:
The vendor has created patches to address this issue. Users of affected packages should contact the vendor for further information on obtaining fixes.
References
Metasploit Framework MSFWeb Defanged Mode Restriction Bypass Vulnerability
References:
References:
- [framework] msfweb "refang" security update (H D Moore
) - Metasploit Framework Homepage (Metasploit Framework)