CVE
- Id
- 72174
- CVE No.
- CVE-2014-4877
- Status
- Candidate
- Description
- Absolute path traversal vulnerability in GNU Wget before 1.16, when recursion is enabled, allows remote FTP servers to write to arbitrary files, and consequently execute arbitrary code, via a LIST response that references the same filename within two entries, one of which indicates that the filename is for a symlink.
- Phase
- Assigned (20140710)
- Votes
- None (candidate not yet proposed)
- Comments
Related CVE References
Related JVN
Id | JVN No. | Title | Summary | CVE No. | CVE Id | CVSS_v2 | CVSS_v3 | JVN URL | Actions |
---|---|---|---|---|---|---|---|---|---|
17127 | JVNDB-2014-006002 | Android 用 CPWORLD Close Protection World アプリケーションにおけるサーバになりすまされる脆弱性 | Android 用 CPWORLD Close Protection World (別名 com.tapatalk.closeprotectionworldcom) アプリケーションは、SSL サーバからの X.509 証明書を検証しないため、サーバになりすまされ、重要な情報を取得される脆弱性が存在します。 | CVE-2014-4885 | 72174 | 5.4 | http://jvndb.jvn.jp/ja/contents/2014/JVNDB-2014-006002.html | View |