- Identify blacklisting
- Identify whitelisting
- Fuzz for allowed extensions
- Fuzz for double & reverse extensions
- Try injecting MIME, but I prefer to just use actually image file and inject php code inside of it.
- If we don’t know the uploaded directory, use SVG XXE to find out.
PHP Server
# Less known PHP extensions