VYPR
Unrated severityNVD Advisory· Published Dec 18, 2002· Updated Apr 16, 2026

CVE-2002-1344

CVE-2002-1344

Description

Directory traversal vulnerability in wget before 1.8.2-4 allows a remote FTP server to create or overwrite files as the wget user via filenames containing (1) /absolute/path or (2) .. (dot dot) sequences.

Affected products

8
  • GNU/Wget7 versions
    cpe:2.3:a:gnu:wget:1.5.3:*:*:*:*:*:*:*+ 6 more
    • cpe:2.3:a:gnu:wget:1.5.3:*:*:*:*:*:*:*
    • cpe:2.3:a:gnu:wget:1.6:*:*:*:*:*:*:*
    • cpe:2.3:a:gnu:wget:1.7:*:*:*:*:*:*:*
    • cpe:2.3:a:gnu:wget:1.7.1:*:*:*:*:*:*:*
    • cpe:2.3:a:gnu:wget:1.8:*:*:*:*:*:*:*
    • cpe:2.3:a:gnu:wget:1.8.1:*:*:*:*:*:*:*
    • cpe:2.3:a:gnu:wget:1.8.2:*:*:*:*:*:*:*
  • cpe:2.3:h:sun:cobalt_raq_xtr:*:*:*:*:*:*:*:*

Patches

0

No patches discovered yet.

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

References

17

News mentions

0

No linked articles in our index yet.