extension-filter

1 article
sort: new top best
clear filter
0 7/10

A race condition vulnerability in a web application's file upload feature allowed RCE by exploiting a 2-second window where uploaded files were stored locally before being moved to S3. The modify.php endpoint lacked extension filtering present in upload.php, enabling PHP shell upload followed by rapid re-requests to execute the file during the local storage window before S3 migration.

YoKo Kho Faisal Yudo Hernawan Tomi Amazon S3 upload.php modify.php
medium.com · devanshbatham/Awesome-Bugbounty-Writeups · 22 hours ago · details