EC-Council Certified Ethical Hacker (CEH) v12Web Application HackingHard

A web application allows users to upload images for their profile. During a security audit, it was discovered that the application checks the file extension on the client side (JavaScript) and then again on the server side by simply checking the MIME type provided in the HTTP request header. An attacker uploads a file named `profile.php.jpg` with a valid JPEG MIME type. Upon successful upload, the attacker can execute arbitrary PHP code by requesting `profile.php.jpg` directly. Which specific type of vulnerability has been exploited?

  1. AInsecure Direct Object Reference (IDOR)
  2. BArbitrary File Upload with MIME Type Bypass
  3. CBroken Access Control
  4. DCross-Site Request Forgery (CSRF)
Show answer & explanation

Correct answer: B. Arbitrary File Upload with MIME Type Bypass

The scenario describes an Arbitrary File Upload vulnerability where the attacker bypassed the server's MIME type check (which is easily spoofed in the HTTP header) and the client-side extension check by using a double extension. This allowed the execution of server-side code.

Why the other options are wrong

  • A. IDOR involves accessing resources directly without proper authorization checks, not file uploads.
  • C. Broken Access Control is a broader category; this is a specific type of vulnerability within it, but 'Arbitrary File Upload' is more precise.
  • D. CSRF forces an authenticated user to submit an unwanted request, which is unrelated to file uploads.

Arbitrary File Upload

Arbitrary File Upload vulnerabilities allow an attacker to upload executable files (e.g., scripts, web shells) to a web server, which can lead to remote code execution.

  • Often exploited by bypassing client-side and weak server-side validation (e.g., extension, MIME type).
  • Can result in complete compromise of the web server.
  • Mitigated by strict server-side validation, renaming files, and storing uploads outside the web root.

Memory trick: Uploads Need Rigorous Verification.

More Web Application Hacking questions