CVE-2002-1344

7 documents7 sources
Severity
5.0MEDIUM
EPSS
0.9%
top 24.36%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedDec 18
Latest updateMay 3

Description

Directory traversal vulnerability in wget before 1.8.2-4 allows a remote FTP server to create or overwrite files as the wget user via filenames containing (1) /absolute/path or (2) .. (dot dot) sequences.

CVSS vector

AV:N/AC:L/C:N/I:P/A:NExploitability: 10.0 | Impact: 2.9

Affected Packages2 packages

Debianwget< 1.8.2-8+3
NVDgnu/wget7 versions+6

Patches

🔴Vulnerability Details

3
GHSA
GHSA-m2vp-q7mm-qrpv: Directory traversal vulnerability in wget before 12022-05-03
OSV
CVE-2002-1344: Directory traversal vulnerability in wget before 12002-12-18
CVEList
CVE-2002-1344: Directory traversal vulnerability in wget before 12002-12-11

📋Vendor Advisories

2
Red Hat
security flaw2002-12-10
Debian
CVE-2002-1344: wget - Directory traversal vulnerability in wget before 1.8.2-4 allows a remote FTP ser...2002

💬Community

1
Bugzilla
CVE-2002-1344 security flaw2018-08-16