godoc icon indicating copy to clipboard operation
godoc copied to clipboard

文件上传没校验后缀

Open cute-angelia opened this issue 2 years ago • 0 comments

上传接口缺乏验证,攻击者可以绕过认证和后缀名检测直接上传webshell,并在此基础上进一步植入DDoS和挖矿代码等恶意程序,执行任意文件。

cute-angelia avatar Apr 07 '22 02:04 cute-angelia