CompTIA PenTest+ (PT0-003)Attacks and ExploitsMedium

A penetration tester is performing a web application assessment. They discover a form that allows users to upload profile pictures. Upon inspecting the HTTP requests, they notice that while the client-side validation enforces `.jpg` or `.png` extensions, the server-side code does not adequately validate the file type or contents. The tester attempts to upload a file named `shell.php` with PHP code designed to execute commands on the server. Which vulnerability is the tester attempting to exploit?

  1. ASQL Injection
  2. BFile Upload Vulnerability
  3. CCross-Site Scripting (XSS)
  4. DDirectory Traversal
Show answer & explanation

Correct answer: B. File Upload Vulnerability

This scenario describes a classic File Upload Vulnerability. When a web application allows users to upload files without proper validation of file type, size, or content, an attacker can upload malicious files (like a web shell) that can then be executed on the server, leading to remote code execution.

Why the other options are wrong

  • A. SQL Injection targets databases by injecting malicious SQL queries, unrelated to file uploads.
  • C. XSS involves injecting client-side scripts, not server-side executable files.
  • D. Directory Traversal involves accessing files outside the intended directory via path manipulation, not uploading malicious files.

File Upload Vulnerability

A web application vulnerability that occurs when an application allows users to upload files without sufficient validation of the file type, size, or content. This can lead to remote code execution if a malicious file (e.g., a web shell) is uploaded and executed on the server.

  • Lack of proper server-side file validation.
  • Allows upload of malicious file types (e.g., `.php`, `.jsp`, `.asp`).
  • Can lead to Remote Code Execution (RCE).

Memory trick: Web app flaws: XSS for clients, SQL for data, Uploads for shells, Traversal for paths.

More Attacks and Exploits questions