File upload flaws

intermediateWeb

TL;DR

File upload flaws let an attacker put a dangerous file where it can do harm — classically a web shell that then runs on the server. The fix is to validate type properly, store uploads outside the web root, and never execute them.

Only test apps you’re authorised to test.

What it is

Anywhere an app lets you upload a file — an avatar, a document, an attachment — is a place where the wrong file, stored in the wrong place, can be trouble. The worst case is a file that the server will execute.

How it works

Weak checks are the theme: trusting the file extension, trusting the content-type header the browser sends, or storing uploads in a folder the web server will happily execute. If those line up, an uploaded script can become code running on the server.

How to test for it

How to fix it

Reference: the OWASP File Upload cheat sheet.

← Back to Web