Severity : |
High
|
Published : |
2014-10-29
|
Modified : |
2015-04-02
|
Base Score : |
9.3
|
Details : |
Absolute path traversal vulnerability in GNU Wget before 1.16, when recursion is enabled, allows remote FTP servers to write to arbitrary files, and consequently execute arbitrary code, via a LIST response that references the same filename within two entries, one of which indicates that the filename is for a symlink.
|
Product/Version : |
Carrier Grade CGE 7.0
Pro 4.x
CGE 4.x
Mobilinux 4.x
Carrier Grade CGE 6.0
|
|