File-Upload
File extension
Payloads
Content type
Content length
Impact by extension
File name
Other Test Cases
Web shell upload via extension blacklist bypass [Overriding the server configuration]
Remote code execution via polyglot web shell upload
File Upload Exploitation
SVG file To XSS
Open Redirect when uploading svg files
Top Upload reports from HackerOne:
Remote Code Execution on www.semrush.com/my_reports on Logo upload to Semrush - 792 upvotes, $0
Webshell via File Upload on ecjobs.starbucks.com.cn to Starbucks - 673 upvotes, $0
Blind XSS on image upload to CS Money - 412 upvotes, $1000
Unrestricted file upload on [ambassador.mail.ru] to Mail.ru - 404 upvotes, $3000
Unrestricted file upload leads to Stored XSS to Visma Public - 268 upvotes, $250
SSRF leaking internal google cloud data through upload function [SSH Keys, etc..] to Vimeo - 249 upvotes, $0
Arbitrary File Upload to Stored XSS to Visma Public - 245 upvotes, $250
Unrestricted File Upload Leads to RCE on mobile.starbucks.com.sg to Starbucks - 225 upvotes, $0
Admin Management - Login Using Default Password - Leads to Image Upload Backdoor/Shell to Razer - 199 upvotes, $200
External SSRF and Local File Read via video upload due to vulnerable FFmpeg HLS processing to TikTok - 139 upvotes, $2727
Unrestricted file upload in www.semrush.com > /my_reports/api/v1/upload/image to Semrush - 124 upvotes, $0
User can upload files even after closing his account to Basecamp - 114 upvotes, $0
XXE Injection through SVG image upload leads to SSRF to Zivver - 112 upvotes, $0
Insecure file upload in xiaoai.mi.com Lead to Stored XSS to Xiaomi - 107 upvotes, $0
Unrestricted File Upload on https://partner.tiktokshop.com/wsos_v2/oec_partner/upload to TikTok - 98 upvotes, $0
[insideok.ru] Remote Command Execution via file upload. to ok.ru - 94 upvotes, $0
Avatar upload allows arbitrary file overwriting to Mail.ru - 88 upvotes, $750
Unrestricted file upload leads to Stored XSS to GitLab - 82 upvotes, $0
Unauthenticated user can upload an attachment to the last updated report draft to HackerOne - 80 upvotes, $0
XSS from arbitrary attachment upload. to Qulture.Rocks - 74 upvotes, $0
Open s3 bucket allows for public upload to Augur - 73 upvotes, $100
SSRF and local file disclosure by video upload on https://www.redtube.com/upload to Pornhub - 61 upvotes, $500
Cross site scripting via file upload in subdomain ads.tiktok.com to TikTok - 59 upvotes, $500
Unrestricted file upload when creating quotes allows for Stored XSS to Visma Public - 57 upvotes, $250
Singapore - Unrestricted File Upload Leads to XSS on campaign.starbucks.com.sg/api/upload to Starbucks - 57 upvotes, $0
Stored XSS on upload files leads to steal cookie to Palo Alto Software - 56 upvotes, $0
SSRF and local file disclosure by video upload on https://www.tube8.com/ to Pornhub - 53 upvotes, $500
Unrestricted File Upload Results in Cross-Site Scripting Attacks to Uber - 53 upvotes, $0
SSRF in VCARD photo upload functionality to Open-Xchange - 49 upvotes, $850
Last updated