Directory Traversal Vulnerability in Rapid7 Metasploit
CVE-2017-5228
What is CVE-2017-5228?
Rapid7 Metasploit, specifically versions before 4.13.0-2017020701, is susceptible to a directory traversal vulnerability in the Meterpreter stdapi Dir.download() function. This vulnerability can be exploited by leveraging a specially-crafted build of Meterpreter, enabling unauthorized write access to arbitrary directories within the Metasploit console. The exploitation occurs with the same permissions as the running Metasploit instance, posing risks to directory integrity and confidentiality.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
Affected Version(s)
Metasploit All versions prior to version 4.13.0-2017020701
References
CVSS V3.1
Timeline
Vulnerability published
Vulnerability Reserved
