File Overwrite Vulnerability in Wget by GNU
CVE-2004-1487

Currently unrated

Key Information:

Vendor

Gnu

Status
Vendor
CVE Published:
27 April 2005

What is CVE-2004-1487?

Wget versions 1.8.x and 1.9.x are susceptible to a vulnerability that allows a remote attacker to overwrite files due to improper handling of redirection URLs. Specifically, the flaw occurs when a malicious web server provides a redirection URL that contains a sequence leading to a file path using '..', which circumvents the application's internal filtering mechanisms. As a result, an attacker can exploit this weakness to overwrite files on the victim's system, potentially leading to further compromise or data loss.

References

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.