> ## Documentation Index
> Fetch the complete documentation index at: https://rootea.es/llms.txt
> Use this file to discover all available pages before exploring further.

# Remote code execution via web shell upload

> PortSwigger Web Security Academy lab: Remote code execution via web shell upload. Topic: File Upload Vulnerabilities.

# Remote code execution via web shell upload

<p className="machine-summary"><span className="prompt"><code>\$ tldr</code></span> PortSwigger · File Upload Vulnerabilities</p>

<div className="machine-meta">
  | ·            | ·                                                                                                                   |
  | ------------ | ------------------------------------------------------------------------------------------------------------------- |
  | Platform     | PortSwigger Web Security Academy                                                                                    |
  | Topic        | File Upload Vulnerabilities                                                                                         |
  | Difficulty   | <span className="dbadge dbadge-easy">APPRENTICE</span>                                                              |
  | Official lab | [Open](https://portswigger.net/web-security/file-upload/lab-file-upload-remote-code-execution-via-web-shell-upload) |
</div>

## Solve the lab

| Language | Author          | Format | Link                                                                                                                |
| -------- | --------------- | ------ | ------------------------------------------------------------------------------------------------------------------- |
| 🇬🇧 EN  | **PortSwigger** | Texto  | [Open](https://portswigger.net/web-security/file-upload/lab-file-upload-remote-code-execution-via-web-shell-upload) |

## Resources by skill

| Skill                       | Source      | Link                                                                          |
| --------------------------- | ----------- | ----------------------------------------------------------------------------- |
| File Upload Vulnerabilities | PortSwigger | [Open](https://portswigger.net/web-security/file-upload)                      |
| Remote Code Execution (RCE) | HackTricks  | [Open](https://book.hacktricks.wiki/en/pentesting-web/command-injection.html) |

## Related skills

[File Upload Vulnerabilities](/en/skills/file-upload) · [Remote Code Execution (RCE)](/en/skills/rce)

***

## Comments & tips

Solved this lab a different way? Share it here — comments live in [GitHub Discussions](https://github.com/FFuson/HTB_Writeups/discussions).

<div className="rootea-giscus-wrap" data-giscus-term="lab:file-upload-file-upload-remote-code-execution-via-web-shell-upload" data-giscus-lang="en" />

*Last updated: 2026-05-08*

<script type="application/ld+json">
  {`{"@context":"https://schema.org","@type":"TechArticle","name":"Remote code execution via web shell upload","headline":"Remote code execution via web shell upload — PortSwigger lab index","url":"https://rootea.es/en/portswigger/labs/file-upload/file-upload-remote-code-execution-via-web-shell-upload","inLanguage":"en","about":[{"@type":"Thing","name":"PortSwigger Web Security Academy"},{"@type":"Thing","name":"File Upload Vulnerabilities"}],"isPartOf":{"@type":"WebSite","name":"rootea.es","url":"https://rootea.es"},"author":{"@type":"Organization","name":"rootea.es"}}`}
</script>
