MIME Sniffing: Why Content-Type Lies

MIME Sniffing: Why Content-Type Lies

Your upload endpoint trusts the header “Content-Type: image/jpeg,” and one of your users can change the name of payload.exe to cute.jpg and bypass your first checkpoint. Browsers attempt self-defence through