Security Advisory

CVE-2014-4877

CVE vulnerability detail - eXtreme Datacenter Security Operations

Published 2014-10-29 10:00:00
Last updated 2024-08-06 11:27:36
Assigner certcc
CVSS score not scored
State PUBLISHED

Description

Absolute path traversal vulnerability in GNU Wget before 1.16, when recursion is enabled, allows remote FTP servers to write to arbitrary files, and consequently execute arbitrary code, via a LIST response that references the same filename within two entries, one of which indicates that the filename is for a symlink.