🚨 GitHub 监控消息提醒
🚨 发现关键词: #RCE
📦 项目名称: -Security-Patch-File-Upload-Vulnerability-RCE-
👤 项目作者: ayoproxy
🛠 开发语言: None
⭐ Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-02-03 11:59:42
📝 项目描述:
🔗 点击访问项目地址
🚨 发现关键词: #RCE
📦 项目名称: -Security-Patch-File-Upload-Vulnerability-RCE-
👤 项目作者: ayoproxy
🛠 开发语言: None
⭐ Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-02-03 11:59:42
📝 项目描述:
Fixed critical RCE vulnerability in `upload_proof_file` by implementing strict server-side extension validation and secure file renaming. The logic no longer trusts client-side MIME types, ensuring malicious PHP scripts cannot be uploaded or executed. Validates against a strict allowlist (jpg, png, pdf) and sanitizes filenames.🔗 点击访问项目地址