
CVE-2017-8809 Docker - RFD(Reflected File Download) for MediaWiki
A remote user can create a specially crafted URL for the target site that, when loaded by the target user, will cause the 'api.php' script to download a file containing shell commands [CVE-2017-8809]. The file will be served by the target site.
$ docker-compose up
Access trap page (http://127.0.0.1:8080/poc.html)
Click "Click here"
$wgServer variable in mediawiki/LocalSettings.php.admin / pass1234.