Collected research
FUSE: Finding File Upload Bugs via Penetration Testing
FUSE mutates file upload requests so they pass a web application's content-filtering checks while preserving the uploaded file's execution semantics, exposing unrestricted file upload and unrestricted executable file upload bugs. Across 33 real PHP applications it found 30 previously unreported remote code execution flaws, 15 of which received CVEs.
Record
- Researcher
- Taekjin Lee, Seongil Wi, Suyoung Lee and Sooel Son
- Published by
- NDSS Symposium
- Topic
- Server
In the archive
Related sources
- NDSS 2020 FUSE: Finding File Upload Bugs via Penetration Testing
- NDSS 2020 FUSE: Finding File Upload Bugs via Penetration Testing
Tags
This page is the archive's own catalogue record. The research is the work of Taekjin Lee, Seongil Wi, Suyoung Lee and Sooel Son, first published at the original source. Preserved copies are kept so the citation survives its host; this one was last captured on .