CVE-2016-7098
HIGHwget < 1.17 - Race Condition in Recursive/Mirroring Mode
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2016-7098. PoCs published by Dawid Golunski.
AI-analyzed exploit summary This exploit demonstrates a race condition in GNU Wget < 1.18 where the access list (-A) check is bypassed by delaying the HTTP response, allowing an attacker to upload a malicious file before it is deleted. The PoC sets up a web server to serve a PHP webshell and triggers its execution before Wget removes it.
Description
Race condition in wget 1.17 and earlier, when used in recursive or mirroring mode to download a single file, might allow remote servers to bypass intended access list restrictions by keeping an HTTP connection open.
Exploits (1)
This exploit demonstrates a race condition in GNU Wget < 1.18 where the access list (-A) check is bypassed by delaying the HTTP response, allowing an attacker to upload a malicious file before it is deleted. The PoC sets up a web server to serve a PHP webshell and triggers its execution before Wget removes it.
References (8)
Scores
CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H