High severity7.1NVD Advisory· Published Mar 2, 2017· Updated Jun 17, 2026
CVE-2017-5231
CVE-2017-5231
Description
All editions of Rapid7 Metasploit prior to version 4.13.0-2017020701 contain a directory traversal vulnerability in the Meterpreter stdapi CommandDispatcher.cmd_download() function. By using a specially-crafted build of Meterpreter, it is possible to write to an arbitrary directory on the Metasploit console with the permissions of the running Metasploit instance.
Affected products
3cpe:2.3:a:rapid7:metasploit:*:*:*:*:*:*:*:*+ 2 more
- cpe:2.3:a:rapid7:metasploit:*:*:*:*:*:*:*:*range: <=4.13.19
- (no CPE)range: <4.13.0-2017020701
- (no CPE)range: All versions prior to version 4.13.0-2017020701
Patches
Vulnerability mechanics
References
2News mentions
0No linked articles in our index yet.