Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

arbitrary file upload #1

Open
veo opened this issue Apr 26, 2020 · 0 comments
Open

arbitrary file upload #1

veo opened this issue Apr 26, 2020 · 0 comments
Assignees
Labels
bug Something isn't working

Comments

@veo
Copy link

veo commented Apr 26, 2020

Users can upload files to their own designated directory, which will cause security problems
image

Uploading to these files in Linux will cause RCE:

~/.ssh/authorized_keys
/etc/cron.d/*
/var/spool/cron/*
/etc/crontab

POC:
image

file in /etc
image

@chenhg5 chenhg5 self-assigned this Sep 14, 2020
@chenhg5 chenhg5 added the bug Something isn't working label Sep 14, 2020
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
bug Something isn't working
Projects
None yet
Development

No branches or pull requests

2 participants