Web App - Insecure File Upload
Insecure file upload - Basic bypass
<script>
function validateFileInput(input) {
var validExtensions = ['jpg', 'png'];
var fileName = input.files[0].name;
var fileNameExt = fileName.substr(fileName.lastIndexOf('.') + 1);
if (!validExtensions.includes(fileNameExt.toLowerCase())) {
input.value = '';
alert("Only '.jpg' and '.png' files are allowed.");
}
}
</script>

Insecure file upload - Magic bytes



Insecure file upload - Challenge


Last updated