Skip to content

arbitrary file upload #1

@veo

Description

@veo

Users can upload files to their own designated directory, which will cause security problems
image

Uploading to these files in Linux will cause RCE:

~/.ssh/authorized_keys
/etc/cron.d/*
/var/spool/cron/*
/etc/crontab

POC:
image

file in /etc
image

Metadata

Metadata

Assignees

Labels

bugSomething isn't working

Type

No type

Projects

No projects

Milestone

No milestone

Relationships

None yet

Development

No branches or pull requests

Issue actions