DVWA part 3: uploading arbitrary files
1 introduction of test environment
The test environment is the DVWA module in the OWASP environment
2 Test description
Since the implementation code of the file upload function does not strictly limit the file suffixes and file types uploaded by users, allowing users to upload arbitrary PHP files to a directory accessible through Web and passing these files to the PHP interpreter, arbitrary PHP scripts can be executed on the remote server.
3 Test steps
Upload a php*** file, because the website does not filter the uploaded file, so you can upload php*** successfully.
Access * files, and the location of * files is: http://1.1.1.1/dvwa/hackable/uploads/x.php