Back to search
CVE-2017-5228
Published: Mar 2, 2017
Modified: Aug 5, 2024
PUBLISHED
Description
All editions of Rapid7 Metasploit prior to version 4.13.0-2017020701 contain a directory traversal vulnerability in the Meterpreter stdapi Dir.download() function. By using a specially-crafted build of Meterpreter, it is possible to write to an arbitrary directory on the Metasploit console with the permissions of the running Metasploit instance.
| Vendor | Product | Versions |
|---|---|---|
Rapid7 | Metasploit | affected All versions prior to version 4.13.0-2017020701 |
References
96954
vdb-entry
x_refsource_BID
Security Training
Train your team to recognize and prevent security threats with our comprehensive security awareness program.
Start TrainingVulnerability Scanning
Discover vulnerabilities in your applications and infrastructure before attackers do.
Scan Now