
@intigriti its clear that the name is user controlled, what one can do is simply just add ../../ for path traversal... but i found out this CVE-2015-2348 and https://shorturl.at/4VRnM basically use a null byte in filename to save it as a .php and boom issue was the move_uploaded_file func
Post summary
The user references CVE-2015-2348, links to a PoC, and explains a null-byte filename exploitation using move_uploaded_file.
