Web Hack List

Collected research

FUSE: Finding File Upload Bugs via Penetration Testing

FUSE mutates file upload requests so they pass a web application's content-filtering checks while preserving the uploaded file's execution semantics, exposing unrestricted file upload and unrestricted executable file upload bugs. Across 33 real PHP applications it found 30 previously unreported remote code execution flaws, 15 of which received CVEs.

Record

Researcher
Taekjin Lee, Seongil Wi, Suyoung Lee and Sooel Son
Published by
NDSS Symposium
Topic
Server

In the archive

Related sources

Tags

This page is the archive's own catalogue record. The research is the work of Taekjin Lee, Seongil Wi, Suyoung Lee and Sooel Son, first published at the original source. Preserved copies are kept so the citation survives its host; this one was last captured on .