C4o

Results 4 comments of C4o

Files can be uploaded in `/srv/pillar/` by default without directory traversal. So only if I find favicon.ico, I can overwrite it. ``` curl -k --header "Content-Type: application/json" \ --request POST...

However, I cannot find other static files that can be easily detected with http request like *.png, *.jpg, *.js...So this way may not work. But this vulnerability can be detected...