-
Notifications
You must be signed in to change notification settings - Fork 738
Closed
Labels
securityExploits, attacks, dangerous leaks.Exploits, attacks, dangerous leaks.
Description
-
It's possible to upload php file by changing extension of image with php code payload. While uploading file you can change extension of uploaded file to php and you can bypass mime type check by concatenating php code binarily to image file or to meta data of image.
More on video attached. -
XSS - while renaming file, you can paste xss payload and it will be stored on the server and run on userside.
MaxKorlaar, winnerawan and Alex00Sam
Metadata
Metadata
Assignees
Labels
securityExploits, attacks, dangerous leaks.Exploits, attacks, dangerous leaks.