CVE-2014-4877
GNU Wget <1.16 - Path Traversal
Title source: llmDescription
Absolute path traversal vulnerability in GNU Wget before 1.16, when recursion is enabled, allows remote FTP servers to write to arbitrary files, and consequently execute arbitrary code, via a LIST response that references the same filename within two entries, one of which indicates that the filename is for a symlink.
Exploits (1)
metasploit
WORKING POC
by hdm · rubypoc
https://github.com/rapid7/metasploit-framework/blob/master/modules/auxiliary/server/wget_symlink_file_write.rb
References (22)
... and 2 more
Scores
EPSS
0.7431
EPSS Percentile
98.9%
Details
CWE
CWE-22
Status
published
Products (8)
gnu/wget
1.12
gnu/wget
1.13
gnu/wget
1.13.1
gnu/wget
1.13.2
gnu/wget
1.13.3
gnu/wget
1.13.4
gnu/wget
1.14
gnu/wget
< 1.15
Published
Oct 29, 2014
Tracked Since
Feb 18, 2026