Skip to content

CVE-2017-8809 Docker - RFD(Reflected File Download) for MediaWiki

Notifications You must be signed in to change notification settings

motikan2010/CVE-2017-8809_MediaWiki_RFD

Folders and files

NameName
Last commit message
Last commit date

Latest commit

 

History

2 Commits
 
 
 
 
 
 
 
 
 
 

Repository files navigation

CVE-2017-8809 - RFD(Reflected File Download) for MediaWiki

A remote user can create a specially crafted URL for the target site that, when loaded by the target user, will cause the 'api.php' script to download a file containing shell commands [CVE-2017-8809]. The file will be served by the target site.

Environment

  • Google Chrome 79.0
  • MediaWiki 1.29.1

Using

  1. Run
$ docker-compose up
  1. Access trap page (http://127.0.0.1:8080/poc.html)

  2. Click "Click here"

Note

  • If change container port, edit $wgServer variable in mediawiki/LocalSettings.php.
  • MediaWiki Account admin / pass1234.

References

About

CVE-2017-8809 Docker - RFD(Reflected File Download) for MediaWiki

Resources

Stars

Watchers

Forks

Releases

No releases published

Packages

No packages published