Vulnerabilities
Vulnerable Software
Gnu:  >> Wget  >> 1.12  Security Vulnerabilities
Absolute path traversal vulnerability in GNU Wget before 1.16, when recursion is enabled, allows remote FTP servers to write to arbitrary files, and consequently execute arbitrary code, via a LIST response that references the same filename within two entries, one of which indicates that the filename is for a symlink.
CVSS Score
9.3
EPSS Score
0.491
Published
2014-10-29
GNU Wget 1.12 and earlier uses a server-provided filename instead of the original URL to determine the destination filename of a download, which allows remote servers to create or overwrite arbitrary files via a 3xx redirect to a URL with a .wgetrc filename followed by a 3xx redirect to a URL with a crafted filename, and possibly execute arbitrary code as a consequence of writing to a dotfile in a home directory.
CVSS Score
6.8
EPSS Score
0.037
Published
2010-07-06


Contact Us

Shodan ® - All rights reserved