Web Application Guest Blog: From File Upload to RCE
(Author’s Note: This vulnerability was found during testing on Synack. I have anonymized, altered, or removed all detail about the customer to keep this information confidential in line with Synack policies.) TL;DR Image file upload functionality doesn’t validate a file extension but validates Content-type and a content of a file. Application sets Content-type of HTTP […]


