V
Scaner-VS
HomeCatalogSourcesCWECAPECATT&CKMitigationsProductsVendorsDocs
CVE-2004-1488
DEB
MediumConfirmedExploit available

wget 1.8.x and 1.9.x does not filter or quote control characters when displaying HTTP responses to the terminal, which may allow remote mal…

CVSS
5.0
Medium
EPSS
0.12
p95
Published
2004-01-01
Updated
2004-01-01
Description

wget 1.8.x and 1.9.x does not filter or quote control characters when displaying HTTP responses to the terminal, which may allow remote malicious web servers to inject terminal escape sequences and execute arbitrary code.

Affected products
Wget
CVSS vector
AV:N/AC:L/Au:N/C:N/I:P/A:N
Timeline
2004-01-01
Published
2004-01-01
Updated
CVSS 3.1 breakdown
Attack Vector
AV: N
Network (N)
Attack Complexity
AC: L
Low (L)
Authentication
Au: N
None (N)
Confidentiality Impact
C: N
None (N)
Integrity Impact
I: P
Partial
Availability Impact
A: N
None (N)
Exploit indicators
EPSS
0.119 · p95
Known exploited (KEV)
No
Known exploits — Сканер-ВС
24813
exploitdb · https://www.exploit-db.com/exploits/24813
Enterprise
Affected products
ProductVendorStatus
wgetTracked
wgetTracked
wgetTracked
wget*Tracked
Source databases
DEB
CVE
RED