Bug Report

Disclosed: 2016-07-19 00:45:23 By 1337_inj3c70r To drchrono
Unknown
Vulnerability Details
Sir, I want to report a bug in your web which i have found in few minutes ago :) I have registered In your website and i have found a upload option i want to upload some php files but its saying only .pdf file allowed so i have just change my (.php) file extension to (.pdf) first its saying not allowed its not a pdf file or file is corrupted... But when i try to upload it using post data i have successfully uploaded corrupted file here is my proof: https://85aa27de34e32ac9f9e0-e519cb8a62f48aa14df288cdc83ab719.ssl.cf5.rackcdn.com/hipaa_forms/2016/06/b193e25b-3218-4a09-8b09-b17bea6d5a18.pdf its a php shell if a attacker can change the value and successfully upload .php file using http request it can be risk for your webserver :) Thanks
Actions
View on HackerOne
Report Stats
  • Report ID: 142940
  • State: Closed
  • Substate: resolved
  • Upvotes: 3
Share this report