Skip to content
KitploitKITPLOIT
ToolsExploitsBlog
Log in
Submit
ToolsExploitsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

FeedsContactPrivacy© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories
CVE-2017-8809_MediaWiki_RFD — CVE-2017-8809 Docker - RFD(Reflected File Download) for MediaWiki | Kitploit
Tools/GitHubGitHub/motikan2010/cve-2017-8809_mediawiki_rfd
Vulnerability AnalysisExploitationWeb Application ExploitationPenetration TestingLearning & Education
GitHubmotikan2010/cve-2017-8809_mediawiki_rfd

CVE-2017-8809_MediaWiki_RFD

CVE-2017-8809 Docker - RFD(Reflected File Download) for MediaWiki

View Repository
516 years agoNot yet reviewed

Most Popular

View all →

Discover the most used tools by our community.

Explore all tools

Browse our collection of tools

View all tools →
Share

CVE-2017-8809 - RFD(Reflected File Download) for MediaWiki

A remote user can create a specially crafted URL for the target site that, when loaded by the target user, will cause the 'api.php' script to download a file containing shell commands [CVE-2017-8809]. The file will be served by the target site.

Environment

  • Google Chrome 79.0
  • MediaWiki 1.29.1

Using

  1. Run
$ docker-compose up
  1. Access trap page (http://127.0.0.1:8080/poc.html)

  2. Click "Click here"

Note

  • If change container port, edit $wgServer variable in mediawiki/LocalSettings.php.
  • MediaWiki Account admin / pass1234.

References

  • NVD - CVE-2017-8809
  • MediaWiki Multiple Flaws Let Remote Users Modify Data, Obtain Potentially Sensitive Information, and Conduct Cross-Site Scripting Attacks and Let Local Users Obtain Passwords - SecurityTracker
  • ⚓ T128209 Reflected File Download from api.php
  • Fix commit
    • SECURITY: API: Avoid some silliness with browser-guessed filenames · wikimedia/mediawiki@66b21e0
  • 714373 - Ignore <a download> for cross origin URLs - chromium - An open-source project to help move the web forward. - Monorail
Download Tool