URadar: Discovering Unrestricted File Upload Vulnerabilities via Adaptive Dynamic Testing
- 论文题目: URadar: Discovering Unrestricted File Upload Vulnerabilities via Adaptive Dynamic Testing
- 发表期刊: IEEE Transactions on Information Forensics and Security, Vol. 19, 2024
- 作者: Yuanchao Chen, Yuwei Li, Zulie Pan, Yuliang Lu, Juxing Chen, Shouling Ji
- 研究领域: Web安全,文件上传漏洞检测,动态测试
1. 背景介绍
- UFU漏洞(Unrestricted File Upload):UFU漏洞允许攻击者上传恶意文件,可能导致服务器被控制。
- UEFU漏洞(Unrestricted Executable File Upload)