eng.helewa's avatar

RCE through an image file upload

Does anyone has a solution for RCE through an image, presented in the video below by Antti Rössi at Laracon EU 2019??

https://youtu.be/kKGGVGiq2y8?t=895

The vulnerability he presented is about passing a code through the meta data of an image which will be uploaded and then the code executed whenever you execute "get file size". That code will allow a reverse shell to connect to your server and execute all sorts of operations.

BTW I recommend to watch the video from the beginning.

0 likes
1 reply

Please or to participate in this conversation.