vulns.co
/
GKData.io MCP

Back to Playbooks

File Upload to RCE

Turn a file upload into code execution by defeating type/extension checks.

Tags: upload, rce, webshell, bypass

Level: intermediate

Method

  1. Map the upload + retrieval

    Find where the file lands and whether it's web-accessible. No exec path? Look for secondary sinks (image processing, archive extraction).

    Tools: Burp Suite, ffuf

  2. Bypass extension filters

    Try double extensions (.php.jpg), alternate handlers (.phtml, .php5), case tricks, null bytes on legacy stacks, and .htaccess overrides.

  3. Bypass content checks

    Spoof Content-Type, prepend valid magic bytes (GIF89a;), or embed code in EXIF/polyglots to pass MIME/image validation.

    exiftool -Comment='<?php system($_GET[c]); ?>' shell.jpg

    Tools: exiftool

  4. Chain the exotic

    SVG → stored XSS/XXE, ZIP → path traversal (zip-slip), image libs → ImageMagick/Ghostscript RCE.

Field notes

  • If uploads aren't executable, pivot: SVG/HTML for XSS, or overwrite files via traversal in the filename.
  • Test what the CDN/origin does with unknown extensions - behavior often differs.

References