15–25 min Updated

File Upload Vulnerabilities

By Malcolm McDonald Founder, Editor-in-ChiefAuthor of Grokking Web Application Security

File uploads are an easy way for an attacker to inject malicious code into your application.

Prevalence
Common
Exploitability
Moderate
Impact
Harmful

What is a file upload vulnerability?

A file upload vulnerability is a code injection weakness in which an application accepts files without validating their type, contents, name or size, then stores them where they can be executed. Attackers exploit it by uploading a script disguised as a harmless file, such as an image, then requesting it to run code on the server.

What you'll learn

  • Why client-side file type checks do not stop a malicious upload
  • How an uploaded script becomes a web shell on your server
  • How to store, rename and validate uploads so they cannot be executed

Where this lesson counts

OWASP Top 10

PCI DSS 4.0

  • File Upload Vulnerabilities lab

    Mal finds a profile image upload that checks file types only in JavaScript. Watch him disable JavaScript, upload a PHP web shell and run it from its public URL. Then take over: pass commands through the shell to find and read the database config file.

  • How to prevent File Upload Vulnerabilities

    The prevention guide covers six approaches:

    • Segregate Your Uploads
    • Ensure Upload Files Cannot Be Executed
    • Rename Files on Upload
    • Validate File Formats and Extensions
    • Validate the Content-Type Header
    • Use a Virus Scanner
  • File Upload Vulnerabilities quiz

    Two questions. Passing marks the lesson complete.

Sources

  • Directory Traversal

    Ensure file paths are safely interpreted, or hackers can access sensitive files on your server.

  • Command Execution

    If your application calls out to the OS, you need to be sure command strings are securely constructed.

  • Remote Code Execution

    If an attacker can smuggle code into your web-server process, you have a serious problem.

  • Cross-Site Scripting

    If your site allows users to add content, you need to be sure that attackers cannot inject malicious JavaScript.