php 14
- Reflected XSS via Attribute Injection | Echoed
- ZIP Slip Leads to Arbitrary File Write | Zippy
- Path Traversal Leads to Arbitrary File Read | Ohmly
- SVG XXE Leads to Local File Disclosure | Educated
- Unrestricted File Upload Leads to Remote Code Execution | Calliope Gallery
- Local File Inclusion via Template Router | CostThis
- Unrestricted File Upload – Remote Code Execution | Hollow Run Bedding
- Unrestricted File Upload – Remote Code Execution via PHP Extension Bypass | Crosswind
- Local File Inclusion via PHP Stream Wrappers | DocketHive
- XXE Injection – Arbitrary File Disclosure via XML Import | Holloway
- Server-Side Template Injection Leading to Remote Code Execution | Outbox
- Local File Inclusion (LFI) to Sensitive File Disclosure | Mapleton
- MIME Type Filter Bypass – Unrestricted File Upload to RCE | Hackviser Lab
- Unrestricted File Upload – RCE Leading to Database Credential Disclosure | Hackviser Lab