
https://hadrian.io/blog/cve-2025-1220-null-byte-trickery-bypasses-hostname-allowlists-in-php using this exploit, we get path traversal + arbitrary file write -> shell upload
Post summary
The blog post presents a proof‑of‑concept exploit for CVE‑2025‑1220 that enables path traversal and arbitrary file write, allowing shell upload.
