vendor:
wget
by:
Jan Min????
7.5
CVSS
HIGH
Multiple remote vulnerabilities
22
CWE
Product Name: wget
Affected Version From:
Affected Version To:
Patch Exists: NO
Related CWE:
CPE:
Platforms Tested:
2004
Remote vulnerabilities in GNU wget
The vulnerabilities in GNU wget allow attackers to perform directory traversal, arbitrary file overwriting, and execute malicious code by not properly sanitizing user-supplied input and validating file presence before writing to them. An attacker can exploit these issues to overwrite files within the current directory and potentially outside of it, leading to file corruption, denial of service, and further attacks against the affected computer. The vulnerabilities can be exploited by a malicious server.
Mitigation:
Update to the latest version of GNU wget. Avoid downloading files from untrusted sources.