Bypassing Extension

ASP and PHP Extension

Double Extension (weak match)

shell.jpg.php

Reverse Double Extension (Server misconfig)

shell.php.jpg

Character Injection

  • %20

  • %0a

  • %00 for PHP 5.x or earlier

  • %0d0a

  • /

  • .\

  • .

  • : for windows server

Content-Type

content-type.txtarrow-up-right

Mime Type

Last updated