Insecure File Upload

Defaults extensions

PHP

.php
.php2
.php3
.php4
.php5
.php7
.pht
.shtml
.phps
.phar
.phpt
.pgif
.phtml
.phtm
.inc
.htaccess

ASP

JSP

Perl

Coldfusion

Flash

Erland Yaws Web Server

Bypasses

Double extensions

Null byte

Special characters

Content-type Bypass

Magic bytes

Triple equal

Filename Vulnerabilities:

Last updated

Was this helpful?