Directory Traversal Vulnerability in Rapid7 Metasploit
CVE-2017-5231
7.1HIGH
What is CVE-2017-5231?
A directory traversal vulnerability has been identified in Rapid7 Metasploit affecting all editions before version 4.13.0-2017020701. This issue resides in the Meterpreter stdapi CommandDispatcher.cmd_download() function, enabling attackers to exploit specially-crafted Meterpreter builds. Successful exploitation allows unauthorized file write operations to arbitrary directories on the Metasploit console, which can compromise the security integrity of the system.
Affected Version(s)
Metasploit All versions prior to version 4.13.0-2017020701