CVE
- Id
- 5728
- CVE No.
- CVE-2002-1344
- Status
- Candidate
- Description
- Directory traversal vulnerability in wget before 1.8.2-4 allows a remote FTP server to create or overwrite files as the wget user via filenames containing (1) /absolute/path or (2) .. (dot dot) sequences.
- Phase
- Modified (20071129)
- Votes
- ACCEPT(2) Cole, Green | MODIFY(1) Cox
- Comments
- Cox> Addref: REDHAT:RHSA-2002:256
Related CVE References
Id | CVE Id | CVE No. | Reference | Actions |
---|---|---|---|---|
31683 | 5728 | CVE-2002-1344 | BUGTRAQ:20021211 Directory Traversal Vulnerabilities in FTP Clients | View |
31684 | 5728 | CVE-2002-1344 | URL:http://marc.info/?l=bugtraq&m=103962838628940&w=2 | View |
31685 | 5728 | CVE-2002-1344 | VULNWATCH:20021210 Directory Traversal Vulnerabilities in FTP Clients | View |
31686 | 5728 | CVE-2002-1344 | URL:http://archives.neohapsis.com/archives/vulnwatch/2002-q4/0102.html | View |
31687 | 5728 | CVE-2002-1344 | CALDERA:CSSA-2003.003.0 | View |
31688 | 5728 | CVE-2002-1344 | URL:http://www.securityfocus.com/archive/1/archive/1/307045/30/26300/threaded | View |
31689 | 5728 | CVE-2002-1344 | CONECTIVA:CLA-2002:552 | View |
31690 | 5728 | CVE-2002-1344 | URL:http://distro.conectiva.com.br/atualizacoes/?id=a&anuncio=000552 | View |
31691 | 5728 | CVE-2002-1344 | CONECTIVA:CLSA-2002:552 | View |
31692 | 5728 | CVE-2002-1344 | URL:http://distro.conectiva.com/atualizacoes/?id=a&anuncio=000552 | View |
31693 | 5728 | CVE-2002-1344 | DEBIAN:DSA-209 | View |
31694 | 5728 | CVE-2002-1344 | URL:https://www.debian.org/security/2002/dsa-209 | View |
31695 | 5728 | CVE-2002-1344 | MANDRAKE:MDKSA-2002:086 | View |
31696 | 5728 | CVE-2002-1344 | URL:http://www.linux-mandrake.com/en/security/2002/MDKSA-2002-086.php | View |
31697 | 5728 | CVE-2002-1344 | OPENPKG:OpenPKG-SA-2003.007 | View |
31698 | 5728 | CVE-2002-1344 | URL:http://www.openpkg.com/security/advisories/OpenPKG-SA-2003.007.html | View |
31699 | 5728 | CVE-2002-1344 | REDHAT:RHSA-2002:229 | View |
31700 | 5728 | CVE-2002-1344 | URL:http://www.redhat.com/support/errata/RHSA-2002-229.html | View |
31701 | 5728 | CVE-2002-1344 | REDHAT:RHSA-2002:256 | View |
31702 | 5728 | CVE-2002-1344 | URL:http://www.redhat.com/support/errata/RHSA-2002-256.html | View |
31703 | 5728 | CVE-2002-1344 | SCO:CSSA-2003-003.0 | View |
31704 | 5728 | CVE-2002-1344 | URL:ftp://ftp.sco.com/pub/security/OpenLinux/CSSA-2003-003.0.txt | View |
31705 | 5728 | CVE-2002-1344 | BUGTRAQ:20021219 TSLSA-2002-0089 - wget | View |
31706 | 5728 | CVE-2002-1344 | URL:http://marc.info/?l=bugtraq&m=104033016703851&w=2 | View |
31707 | 5728 | CVE-2002-1344 | CIAC:N-022 | View |
31708 | 5728 | CVE-2002-1344 | URL:http://www.ciac.org/ciac/bulletins/n-022.shtml | View |
31709 | 5728 | CVE-2002-1344 | CERT-VN:VU#210148 | View |
31710 | 5728 | CVE-2002-1344 | URL:http://www.kb.cert.org/vuls/id/210148 | View |
31711 | 5728 | CVE-2002-1344 | BID:6352 | View |
31712 | 5728 | CVE-2002-1344 | URL:http://www.securityfocus.com/bid/6352 | View |
31713 | 5728 | CVE-2002-1344 | BID:6360 | View |
31714 | 5728 | CVE-2002-1344 | URL:http://www.securityfocus.com/bid/6360 | View |
31715 | 5728 | CVE-2002-1344 | XF:wget-ftp-filename-traversal(10820) | View |
Related JVN
Id | JVN No. | Title | Summary | CVE No. | CVE Id | CVSS_v2 | CVSS_v3 | JVN URL | Actions |
---|---|---|---|---|---|---|---|---|---|
63983 | JVNDB-2002-000310 | FTP クライアントにおけるディレクトリトラバーサルの脆弱性 | 様々なオペレーティングシステムに含まれている wget や FTP クライアントには、 NLST コマンドに対するレスポンスかどうかを適切に検査しない問題により、クライアントの作業ディレクトリを越えたダウンロード先にファイルを転送される脆弱性が存在します。 | CVE-2002-1344 | 5728 | 5 | http://jvndb.jvn.jp/ja/contents/2002/JVNDB-2002-000310.html | View |