Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
N/A
Vulnerability Description
GNU Wget 1.12 and earlier uses a server-provided filename instead of the original URL to determine the destination filename of a download, which allows remote servers to create or overwrite arbitrary files via a 3xx redirect to a URL with a .wgetrc filename followed by a 3xx redirect to a URL with a crafted filename, and possibly execute arbitrary code as a consequence of writing to a dotfile in a home directory.
CVSS Information
N/A
Vulnerability Type
N/A
Vulnerability Title
GNU Wget输入验证漏洞
Vulnerability Description
GNU Wget是GNU计划开发的一套用于在网络上进行下载的自由软件,它支持通过HTTP、HTTPS以及FTP这三个最常见的TCP/IP协议下载。 GNU Wget 1.12以及之前的版本使用服务器提供的文件名而不是原始的URL来确定下载的目标文件名。远程服务器可以利用3xx重定向到含有.wgetrc文件名的URL,紧接着利用3xx重定向到含有伪造的文件名的URL来创建或者覆盖任意的文件,并且可能由于将此写入主目录dotfile中而执行任意代码。
CVSS Information
N/A
Vulnerability Type
N/A