{
  "entrypoint_kind": "library_api",
  "entrypoint_detail": "ThinkPHP Upload->upload() reached by POST /index.php?s=/home/page/uploadImg",
  "service_started": true,
  "healthcheck_passed": true,
  "target_path_reached": true,
  "runtime_stack": ["docker", "php:7.4-apache", "thinkphp-3.2", "showdoc"],
  "proof_artifacts": [
    "runtime_artifacts/http/vuln/request_metadata.txt",
    "runtime_artifacts/http/vuln/controller_lines.txt",
    "runtime_artifacts/http/vuln/controller_upload_flow.txt",
    "runtime_artifacts/http/vuln/upload_response.txt",
    "runtime_artifacts/http/vuln/uploaded_php_files.txt",
    "runtime_artifacts/http/vuln/webshell_exec_response.txt",
    "runtime_artifacts/http/fb77/controller_lines.txt",
    "runtime_artifacts/http/fb77/upload_response.txt",
    "runtime_artifacts/http/e1cd/controller_lines.txt",
    "runtime_artifacts/http/e1cd/upload_response.txt",
    "runtime_artifacts/http/summary.txt"
  ],
  "notes": "Real endpoint trigger proves vulnerable Upload->upload path in v2.8.2 and shows behavior difference after fb77dd4 and e1cd02a"
}
