Skip to content
Vulnerability field guide

File Upload

An upload form that trusts the filename, the declared Content-Type or a file's first bytes can place a server-side script or a scripted SVG on your own origin. Here is how upload validation fails, how to test it safely, and how to build a handler that holds.

1 article 8 min total Overview to advanced techniques