Overview
Also called path traversal, this flaw lets an attacker supply ../ sequences to read or write files outside the web root.\nTargets include /etc/passwd, application configuration, source code and, combined with a write primitive, web shells.\nIt arises whenever a path is built by string concatenation instead of resolved and checked against a whitelist root.
Indicators of Compromise
Signals that suggest this is present on a system.
- ../../ encoded in download parameters
- Config or .env files downloadable
- File-read errors that echo the requested path
Controls that stop it
-
Validate and Constrain All Input
Treat every request as hostile. Reject anything that does not match an allow list, enforce type, length, range and format, and canonicalise before you validate so encoded bypasses cannot slip through. For file uploads, re-encode the image, randomise the name, strip metadata and store outside the web root on a domain that cannot execute code.