Tuesday, September 1, 2020

New vulnerability on the NVD: CVE-2019-5645

By sending a specially crafted HTTP GET request to a listening Rapid7 Metasploit HTTP handler, an attacker can register an arbitrary regular expression. When evaluated, this malicious handler can either prevent new HTTP handler sessions from being established, or cause a resource exhaustion on the Metasploit server.

Published at: September 01, 2020 at 06:15PM
View on website

No comments:

Post a Comment