cbcvebase.
CVE-2016-4971
published 2016-06-30

CVE-2016-4971: GNU wget before 1.18 allows remote servers to write to arbitrary files by redirecting a request from HTTP to a crafted FTP resource.

high8.8CVSS 3.1
AVNACLPRNUIRSUCHIHAH
EXPLOIT
GNU wget before 1.18 allows remote servers to write to arbitrary files by redirecting a request from HTTP to a crafted FTP resource.

Affected

16 ranges
VendorProductVersion rangeFixed in
canonicalubuntu_linux
canonicalubuntu_linux
canonicalubuntu_linux
canonicalubuntu_linux
debianwget< wget 1.18-1 (bookworm)wget 1.18-1 (bookworm)
gnuwget< 1.181.18
gnuwget>= 0 < 1.18-11.18-1
gnuwget>= 0 < 1.18-11.18-1
gnuwget>= 0 < 1.18-11.18-1
gnuwget>= 0 < 1.18-11.18-1
oraclesolaris
oraclesolaris
paloaltopan-os
paloaltonetworkspan-os6.1.0 – 6.1.16
paloaltonetworkspan-os7.0.0 – 7.0.14
paloaltonetworkspan-os7.1.0 – 7.1.9

CVSS provenance

nvdv3.18.8HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
osv8.8HIGH