crypto-trading-platform

1 article
sort: new top best
clear filter
0 6/10

A file upload bypass vulnerability on a crypto trading platform allowing RCE by manipulating Content-Type headers from image/png to text/html, leading to PHP shell execution and database credential extraction for account manipulation. The author demonstrates chaining file upload bypass with RCE and database access to achieve P1 severity.

Mohammed Abdul Raheem Muhammad Khizer Javed OWASP Burp Suite c99 shell
medium.com · devanshbatham/Awesome-Bugbounty-Writeups · 6 hours ago · details