MediaWiki < 1.27.4, 1.28.x < 1.28.3, 1.29.x < 1.29.2 - Reflected File Download via api.php
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2017-8809. PoCs published by motikan2010.
AI-analyzed exploit summary This repository contains a proof-of-concept for CVE-2017-8809, a Reflected File Download (RFD) vulnerability in MediaWiki 1.29.1. The exploit leverages the 'api.php' script to serve a file with shell commands when a crafted URL is accessed by the target user.
Description
api.php in MediaWiki before 1.27.4, 1.28.x before 1.28.3, and 1.29.x before 1.29.2 has a Reflected File Download vulnerability.
Exploits (1)
This repository contains a proof-of-concept for CVE-2017-8809, a Reflected File Download (RFD) vulnerability in MediaWiki 1.29.1. The exploit leverages the 'api.php' script to serve a file with shell commands when a crafted URL is accessed by the target user.
References (3)
Scores
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H