V
Scaner-VS
HomeCatalogSourcesCWECAPECATT&CKMitigationsDocs
CVE-2014-4877
DEB
Medium

Absolute path traversal vulnerability in GNU Wget before 1.16, when recursion is enabled, allows remote FTP servers to write to arbitrary f…

CVSS
4.3
Medium
EPSS
0.74
p98
Published
2014-01-01
Updated
2014-01-01
Description

Absolute path traversal vulnerability in GNU Wget before 1.16, when recursion is enabled, allows remote FTP servers to write to arbitrary files, and consequently execute arbitrary code, via a LIST response that references the same filename within two entries, one of which indicates that the filename is for a symlink.

Tags · CWE
CWE-22
CWE-59
CAPEC-17
CAPEC-35
CAPEC-64
CAPEC-76
CAPEC-78
CAPEC-79
CAPEC-126
CAPEC-132
Affected products
Wget ≤ 1.15Wget
CVSS vector
AV:N/AC:M/Au:N/C:N/I:P/A:N
Timeline
2014-01-01
Published
2014-01-01
Updated
CVSS 3.1 breakdown
Attack Vector
AV: N
Network (N)
Attack Complexity
AC: M
Medium
Authentication
Au: N
None (N)
Confidentiality Impact
C: N
None (N)
Integrity Impact
I: P
Partial
Availability Impact
A: N
None (N)
Exploit indicators
EPSS
0.743 · p98
Known exploited (KEV)
No
MITRE ATT&CK
Inferred via CAPEC
└ via CAPEC-35 · CWE-59
└ via CAPEC-35 · CWE-59
└ via CAPEC-132 · CWE-59
└ via CAPEC-35 · CWE-59
Known exploits — Сканер-ВС
No Сканер-ВС checks registered for this vulnerability yet.
Affected software
ProductVendorStatus
wgetTracked
wgetTracked
wgetTracked
wgetTracked
wgetTracked
wgetTracked
wgetTracked
wget*Tracked
Source databases
DEB
CVE
RED
UBU
Related vulnerabilities