Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-p2w7-gcfj-5p55

Опубликовано: 17 мая 2022
Источник: github
Github: Не прошло ревью

Описание

Absolute path traversal vulnerability in GNU Wget before 1.16, when recursion is enabled, allows remote FTP servers to write to arbitrary files, and consequently execute arbitrary code, via a LIST response that references the same filename within two entries, one of which indicates that the filename is for a symlink.

Absolute path traversal vulnerability in GNU Wget before 1.16, when recursion is enabled, allows remote FTP servers to write to arbitrary files, and consequently execute arbitrary code, via a LIST response that references the same filename within two entries, one of which indicates that the filename is for a symlink.

EPSS

Процентиль: 99%
0.69365
Средний

Дефекты

CWE-22

Связанные уязвимости

ubuntu
почти 11 лет назад

Absolute path traversal vulnerability in GNU Wget before 1.16, when recursion is enabled, allows remote FTP servers to write to arbitrary files, and consequently execute arbitrary code, via a LIST response that references the same filename within two entries, one of which indicates that the filename is for a symlink.

redhat
почти 11 лет назад

Absolute path traversal vulnerability in GNU Wget before 1.16, when recursion is enabled, allows remote FTP servers to write to arbitrary files, and consequently execute arbitrary code, via a LIST response that references the same filename within two entries, one of which indicates that the filename is for a symlink.

nvd
почти 11 лет назад

Absolute path traversal vulnerability in GNU Wget before 1.16, when recursion is enabled, allows remote FTP servers to write to arbitrary files, and consequently execute arbitrary code, via a LIST response that references the same filename within two entries, one of which indicates that the filename is for a symlink.

debian
почти 11 лет назад

Absolute path traversal vulnerability in GNU Wget before 1.16, when re ...

oracle-oval
почти 11 лет назад

ELSA-2014-1764: wget security update (MODERATE)

EPSS

Процентиль: 99%
0.69365
Средний

Дефекты

CWE-22