This is a technical writeup describing an arbitrary file upload vulnerability in Ajax Upload. The author explains how to bypass file extension restrictions by manipulating HTTP headers or using multiple extensions in the filename.
Classification
Writeup 80%
Attack Type
Other
Complexity
Trivial
Reliability
Reliable
Target:Ajax Upload (version not specified)
No auth needed
Prerequisites:Access to the vulnerable Ajax Upload endpoint · Ability to modify HTTP headers or craft filenames