Unrated severityNVD Advisory· Published Aug 24, 2020· Updated Sep 17, 2024
Rapid7 Metasploit Framework Relative Path Traversal in telpho10_credential_dump module
CVE-2020-7377
Description
The Metasploit Framework module "auxiliary/admin/http/telpho10_credential_dump" module is affected by a relative path traversal vulnerability in the untar method which can be exploited to write arbitrary files to arbitrary locations on the host file system when the module is run on a malicious HTTP server.
Affected products
1- Range: 4.12.40
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
1- github.com/rapid7/metasploit-framework/issues/14015mitrex_refsource_CONFIRM
News mentions
0No linked articles in our index yet.