← All CVEs

CVE-2016-4971

high · 8.8

GNU wget before 1.18 allows remote servers to write to arbitrary files by redirecting a request from HTTP to a crafted FTP resource.

8.8
CVSS
46.1%
EPSS (exploit prob.)
99th
EPSS percentile
2016-06-30
Published

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

Affected products

VendorProductAffected versions
gnuwget< 1.18
canonicalubuntu_linux12.04
canonicalubuntu_linux14.04
canonicalubuntu_linux15.10
canonicalubuntu_linux16.04
oraclesolaris10
oraclesolaris11.3
paloaltonetworkspan-os>= 6.1.0, <= 6.1.16
paloaltonetworkspan-os>= 7.0.0, <= 7.0.14
paloaltonetworkspan-os>= 7.1.0, <= 7.1.9

Check a specific version with /api/v1/cve/match.

References

Query this programmatically:

curl https://evil-db.io/api/v1/cve/CVE-2016-4971