CVE-2017-5231

All editions of Rapid7 Metasploit prior to version 4.13.0-2017020701 contain a directory traversal vulnerability in the Meterpreter stdapi CommandDispatcher.cmd_download() function. By using a specially-crafted build of Meterpreter, it is possible to write to an arbitrary directory on the Metasploit console with the permissions of the running Metasploit instance.
Configurations

Configuration 1 (hide)

cpe:2.3:a:rapid7:metasploit:*:*:*:*:*:*:*:*

History

No history.

Information

Published : 2017-03-02 20:59

Updated : 2023-12-10 12:01


NVD link : CVE-2017-5231

Mitre link : CVE-2017-5231

CVE.ORG link : CVE-2017-5231


JSON object : View

Products Affected

rapid7

  • metasploit
CWE
CWE-22

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')