CVE-2002-1344
published 2002-12-18CVE-2002-1344: Directory traversal vulnerability in wget before 1.8.2-4 allows a remote FTP server to create or overwrite files as the wget user via filenames containing (1)…
PriorityP421medium5CVSS 2.0
AVNACLAuNCNIPAN
EPSS
4.25%
90.0th percentile
Directory traversal vulnerability in wget before 1.8.2-4 allows a remote FTP server to create or overwrite files as the wget user via filenames containing (1) /absolute/path or (2) .. (dot dot) sequences.
Affected
12 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | wget | < wget 1.8.2-8 (bookworm) | wget 1.8.2-8 (bookworm) |
| gnu | wget | — | — |
| gnu | wget | — | — |
| gnu | wget | — | — |
| gnu | wget | — | — |
| gnu | wget | — | — |
| gnu | wget | — | — |
| gnu | wget | — | — |
| gnu | wget | >= 0 < 1.8.2-8 | 1.8.2-8 |
| gnu | wget | >= 0 < 1.8.2-8 | 1.8.2-8 |
| gnu | wget | >= 0 < 1.8.2-8 | 1.8.2-8 |
| gnu | wget | >= 0 < 1.8.2-8 | 1.8.2-8 |
CVSS provenance
nvdv2.05.0MEDIUMAV:N/AC:L/Au:N/C:N/I:P/A:N
osv5.0MEDIUM
vendor_debian5.0MEDIUM
vendor_redhat5.0MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Red Hat
security flaw
vendor_redhat·2002-12-10·CVSS 5.0
CVE-2002-1344 [MEDIUM] security flaw
security flaw
Directory traversal vulnerability in wget before 1.8.2-4 allows a remote FTP server to create or overwrite files as the wget user via filenames containing (1) /absolute/path or (2) .. (dot dot) sequences.
Debian
CVE-2002-1344: wget - Directory traversal vulnerability in wget before 1.8.2-4 allows a remote FTP ser...
vendor_debian·2002·CVSS 5.0
CVE-2002-1344 [MEDIUM] CVE-2002-1344: wget - Directory traversal vulnerability in wget before 1.8.2-4 allows a remote FTP ser...
Directory traversal vulnerability in wget before 1.8.2-4 allows a remote FTP server to create or overwrite files as the wget user via filenames containing (1) /absolute/path or (2) .. (dot dot) sequences.
Scope: local
bookworm: resolved (fixed in 1.8.2-8)
bullseye: resolved (fixed in 1.8.2-8)
forky: resolved (fixed in 1.8.2-8)
sid: resolved (fixed in 1.8.2-8)
trixie: resolved (fixed in 1.8.2-8)
GHSA
GHSA-m2vp-q7mm-qrpv: Directory traversal vulnerability in wget before 1
ghsa_unreviewed·2022-05-03
CVE-2002-1344 [MEDIUM] GHSA-m2vp-q7mm-qrpv: Directory traversal vulnerability in wget before 1
Directory traversal vulnerability in wget before 1.8.2-4 allows a remote FTP server to create or overwrite files as the wget user via filenames containing (1) /absolute/path or (2) .. (dot dot) sequences.
OSV
CVE-2002-1344: Directory traversal vulnerability in wget before 1
osv·2002-12-18·CVSS 5.0
CVE-2002-1344 [MEDIUM] CVE-2002-1344: Directory traversal vulnerability in wget before 1
Directory traversal vulnerability in wget before 1.8.2-4 allows a remote FTP server to create or overwrite files as the wget user via filenames containing (1) /absolute/path or (2) .. (dot dot) sequences.
No detection rules found.
No public exploits indexed.
ftp://ftp.sco.com/pub/security/OpenLinux/CSSA-2003-003.0.txthttp://archives.neohapsis.com/archives/vulnwatch/2002-q4/0102.htmlhttp://distro.conectiva.com.br/atualizacoes/?id=a&anuncio=000552http://distro.conectiva.com/atualizacoes/?id=a&anuncio=000552http://marc.info/?l=bugtraq&m=103962838628940&w=2http://marc.info/?l=bugtraq&m=104033016703851&w=2http://www.ciac.org/ciac/bulletins/n-022.shtmlhttp://www.iss.net/security_center/static/10820.phphttp://www.kb.cert.org/vuls/id/210148http://www.linux-mandrake.com/en/security/2002/MDKSA-2002-086.phphttp://www.openpkg.com/security/advisories/OpenPKG-SA-2003.007.htmlhttp://www.redhat.com/support/errata/RHSA-2002-229.htmlhttp://www.redhat.com/support/errata/RHSA-2002-256.htmlhttp://www.securityfocus.com/archive/1/307045/30/26300/threadedhttp://www.securityfocus.com/bid/6352http://www.securityfocus.com/bid/6360https://www.debian.org/security/2002/dsa-209ftp://ftp.sco.com/pub/security/OpenLinux/CSSA-2003-003.0.txthttp://archives.neohapsis.com/archives/vulnwatch/2002-q4/0102.htmlhttp://distro.conectiva.com.br/atualizacoes/?id=a&anuncio=000552http://distro.conectiva.com/atualizacoes/?id=a&anuncio=000552http://marc.info/?l=bugtraq&m=103962838628940&w=2http://marc.info/?l=bugtraq&m=104033016703851&w=2http://www.ciac.org/ciac/bulletins/n-022.shtmlhttp://www.iss.net/security_center/static/10820.phphttp://www.kb.cert.org/vuls/id/210148http://www.linux-mandrake.com/en/security/2002/MDKSA-2002-086.phphttp://www.openpkg.com/security/advisories/OpenPKG-SA-2003.007.htmlhttp://www.redhat.com/support/errata/RHSA-2002-229.htmlhttp://www.redhat.com/support/errata/RHSA-2002-256.htmlhttp://www.securityfocus.com/archive/1/307045/30/26300/threadedhttp://www.securityfocus.com/bid/6352http://www.securityfocus.com/bid/6360https://www.debian.org/security/2002/dsa-209
2002-12-18
Published