CVE-2014-4877

GNU Wget <1.16 - Path Traversal

Title source: llm

Description

Absolute path traversal vulnerability in GNU Wget before 1.16, when recursion is enabled, allows remote FTP servers to write to arbitrary files, and consequently execute arbitrary code, via a LIST response that references the same filename within two entries, one of which indicates that the filename is for a symlink.

Exploits (1)

metasploit WORKING POC
by hdm · rubypoc
https://github.com/rapid7/metasploit-framework/blob/master/modules/auxiliary/server/wget_symlink_file_write.rb

References (22)

... and 2 more

Scores

EPSS 0.7431
EPSS Percentile 98.9%

Details

CWE
CWE-22
Status published
Products (8)
gnu/wget 1.12
gnu/wget 1.13
gnu/wget 1.13.1
gnu/wget 1.13.2
gnu/wget 1.13.3
gnu/wget 1.13.4
gnu/wget 1.14
gnu/wget < 1.15
Published Oct 29, 2014
Tracked Since Feb 18, 2026