Описание
Directory traversal vulnerability in wget before 1.8.2-4 allows a remote FTP server to create or overwrite files as the wget user via filenames containing (1) /absolute/path or (2) .. (dot dot) sequences.
Ссылки
- US Government Resource
- PatchVendor Advisory
- PatchVendor Advisory
Уязвимые конфигурации
Конфигурация 1
Одно из
cpe:2.3:a:gnu:wget:1.5.3:*:*:*:*:*:*:*
cpe:2.3:a:gnu:wget:1.6:*:*:*:*:*:*:*
cpe:2.3:a:gnu:wget:1.7:*:*:*:*:*:*:*
cpe:2.3:a:gnu:wget:1.7.1:*:*:*:*:*:*:*
cpe:2.3:a:gnu:wget:1.8:*:*:*:*:*:*:*
cpe:2.3:a:gnu:wget:1.8.1:*:*:*:*:*:*:*
cpe:2.3:a:gnu:wget:1.8.2:*:*:*:*:*:*:*
cpe:2.3:h:sun:cobalt_raq_xtr:*:*:*:*:*:*:*:*
EPSS
Процентиль: 72%
0.00764
Низкий
5 Medium
CVSS2
Дефекты
NVD-CWE-Other
Связанные уязвимости
redhat
больше 22 лет назад
Directory traversal vulnerability in wget before 1.8.2-4 allows a remote FTP server to create or overwrite files as the wget user via filenames containing (1) /absolute/path or (2) .. (dot dot) sequences.
debian
больше 22 лет назад
Directory traversal vulnerability in wget before 1.8.2-4 allows a remo ...
github
около 3 лет назад
Directory traversal vulnerability in wget before 1.8.2-4 allows a remote FTP server to create or overwrite files as the wget user via filenames containing (1) /absolute/path or (2) .. (dot dot) sequences.
EPSS
Процентиль: 72%
0.00764
Низкий
5 Medium
CVSS2
Дефекты
NVD-CWE-Other