bugs.debian.org
http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=261755 CVE-2004-1488
GNU Wget 1.x - Multiple Vulnerabilities
Record summary
CVE-2004-1488 has a selected CVSS score of 5.0; EIP currently links 1 catalogued exploit.
Description
wget 1.8.x and 1.9.x does not filter or quote control characters when displaying HTTP responses to the terminal, which may allow remote malicious web servers to inject terminal escape sequences and execute arbitrary code.
Description source: CVE List
Exploitation context
Available material
- Catalogued exploits
- 1
Proofs of concept
1Catalogued exploits
ExploitDBGNU Wget 1.x - Multiple VulnerabilitiesExploitDB exploitby Jan MinarNot analyzed1 file
References
1120041209 wget: Arbitrary file overwriting/appending/creating and other vulnerabilitiesmailing list
http://marc.info/?l=bugtraq&m=110269474112384&w=2 20960Third-party advisory
http://secunia.com/advisories/20960 1012472vdb entry
http://securitytracker.com/id?1012472 SUSE-SR:2006:016Vendor advisory
http://www.novell.com/linux/security/advisories/2006_16_sr.html RHSA-2005:771Vendor advisory
http://www.redhat.com/support/errata/RHSA-2005-771.html 11871vdb entry
http://www.securityfocus.com/bid/11871 wget-terminal-overwrite(18421)vdb entry
https://exchange.xforce.ibmcloud.com/vulnerabilities/18421 nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2004-1488 oval:org.mitre.oval:def:9750vdb entrysignature
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A9750 USN-145-1Vendor advisory
https://usn.ubuntu.com/145-1