Hacker News new | ask | show | jobs
by h33t-l4x0r 272 days ago
I imagine it's supposed to get onto the server by an exploited vulnerable image upload plugin
1 comments

Maybe I don’t understand the scenario fully, but under your assumption there is no need to inject the malicious webshell later.