Web Security Academy Lab: https://portswigger.net/web-security/...
This lab contains a vulnerable image upload function. It doesn't perform any validation on the files users upload before storing them on the server's filesystem.
To solve the lab, upload a basic PHP web shell and use it to exfiltrate the contents of the file /home/carlos/secret. Submit this secret using the button provided in the lab banner.
You can log in to your own account using the following credentials: wiener:peter
On this page of the site you can watch the video online Remote code execution via web shell upload | Web Security Academy with a duration of hours minute second in good quality, which was uploaded by the user Krishnendu Samanta 01 January 1970, share the link with friends and acquaintances, this video has already been watched 4,747 times on youtube and it was liked by 24 viewers. Enjoy your viewing!