BigHugger
sk Skill · elementalsouls

hunt-file-upload

Hunt file upload bugs — RCE via webshell, XSS via SVG/HTML, SSRF via XXE in DOCX, path traversal via filename. Bypass tables (10 techniques): double extension (shell.php.jpg if server checks last ext only), magic bytes spoofing (PNG header on PHP), null byte (shell.php.jpg), case (PHP, .Php, .pHP), .htaccess upload to enable execution, SVG with <script>, HTML/SVG XSS, DOCX with embedded XXE, ZIP slip…

installs 8w
0
30-day movement
starts with the next reading
Related entries
1
Connections
0
xmlbashPython
Host repository
elementalsouls/Claude-BugHunter
Host stars
4,524
Host language
Python