“Bug Bounty Bootcamp #32: Weaponizing File Uploads — From Profile Pictures to Remote Code…
That innocent avatar uploader could be your gateway to the server. Learn to abuse file names, content types, and directory traversal to…Continue reading on InfoSec Write-ups »
Related Vulnerabilities
- CVE-2026-6014: A flaw has been found in D-Link DIR-513 1.10. This issue affects the function formAdvanceSetup of th HIGH
- CVE-2026-5991: A vulnerability was found in Tenda F451 1.0.0.7. Affected by this issue is the function formWrlExtra HIGH
- CVE-2026-6026: A security flaw has been discovered in Totolink A7100RU 7.4cu.2313_b20191024. This vulnerability aff CRITICAL
- CVE-2026-4150: GIMP PSD File Parsing Integer Overflow Remote Code Execution Vulnerability. This vulnerability allow HIGH
- CVE-2026-5998: A flaw has been found in zhayujie chatgpt-on-wechat CowAgent up to 2.0.4. This affects the function MEDIUM
Related Coverage
Threat Actors