Overview
The most direct route from "can upload" to "owns the server": the attacker uploads shell.php, requests it, and executes commands.\nWeak validation checks only the extension or the client-supplied MIME type, both of which are attacker-controlled.\nSafe designs store outside the web root, randomise filenames, re-encode images and serve through a non-executable domain.
Indicators of Compromise
Signals that suggest this is present on a system.
- .php or .aspx accepted in uploads
- Executable files reachable under /uploads
- Double extensions such as image.php.jpg accepted
Controls that stop it
-
Validate and Constrain All Input
Treat every request as hostile. Reject anything that does not match an allow list, enforce type, length, range and format, and canonicalise before you validate so encoded bypasses cannot slip through. For file uploads, re-encode the image, randomise the name, strip metadata and store outside the web root on a domain that cannot execute code.