CVE-2004-1487

8 documents8 sources
Severity
5.0MEDIUM
EPSS
0.7%
top 28.23%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedApr 27
Latest updateApr 29

Description

wget 1.8.x and 1.9.x allows a remote malicious web server to overwrite certain files via a redirection URL containing a ".." that resolves to the IP address of the malicious server, which bypasses wget's filtering for ".." sequences.

CVSS vector

AV:N/AC:L/C:N/I:P/A:NExploitability: 10.0 | Impact: 2.9

Affected Packages2 packages

Debianwget< 1.9.1-11+3
NVDgnu/wget5 versions+4

🔴Vulnerability Details

3
GHSA
GHSA-wh4v-xm5m-9jfg: wget 12022-04-29
OSV
CVE-2004-1487: wget 12005-04-27
CVEList
CVE-2004-1487: wget 12005-02-15

📋Vendor Advisories

3
Ubuntu
wget vulnerabilities2005-06-28
Red Hat
security flaw2004-12-10
Debian
CVE-2004-1487: wget - wget 1.8.x and 1.9.x allows a remote malicious web server to overwrite certain f...2004

💬Community

1
Bugzilla
CVE-2004-1487 security flaw2018-08-16