A penetration testing tool for finding file upload bugs (NDSS 2020)
-
Updated
Mar 30, 2021 - Python
A penetration testing tool for finding file upload bugs (NDSS 2020)
This tool is designed to test for file upload and XXE vulnerabilities by poisoning XLSX files.
This repository is a dockerized PHP application containing some file upload vulnerability challenges (scenarios).
Generate some payload to bypass restriction when you perform a file upload
Award‑Winning Application Security Specialist, Blockchain Security Researcher
Tool for exploiting file upload vulnerabilities in DVWA (Damn Vulnerable Web Application).
Web Penetration Testing : File Upload Vulnerability Dengan Metasploit.
Flask Powered Vulnerable Image Generator
Unrestricted file upload in big file upload functionality in `/main/inc/lib/javascript/bigupload/inc/bigUpload.php` in Chamilo LMS <= v1.11.24 allows unauthenticated attackers to perform stored cross-site scripting attacks and obtain remote code execution via uploading of web shell.
Python tool to create polyglot files for magic byte bypass by merging with valid file formats (JPEG, PNG, PDF, DOCX, MP4, etc.)
File Upload Vulnerability using Lighweight PHP
All associated materials and tasks for the training
This case demonstrates a classic but still deeply effective tactic: the use of an improperly validated file upload to implant a web shell. It wasn’t an exploit. It wasn’t a brute force attack. It was a misused feature — a vulnerable application logic path that let an attacker turn a web server into a foothold.
Add a description, image, and links to the file-upload-vulnerability topic page so that developers can more easily learn about it.
To associate your repository with the file-upload-vulnerability topic, visit your repo's landing page and select "manage topics."