upload vulnerability:
in user profile upload an avatar with a double extension like :
file.php.jpg
once it's done,you gone get an error like:Fatal error: Call to undefined function imagedestroy() in /.
but the last extension (jpg) will be removed by the script, and stored in :...
upload vulnerability:
in user profile upload an avatar with a double extension like :
file.php.jpg
once it's done,you gone get an error like:Fatal error: Call to undefined function imagedestroy() in /.
but the last extension (jpg) will be removed by the script, and stored in :...
[ more ]