High severity Vulnerability

Directory Traversal

Path segments such as ../../ escape the intended folder and expose system files.

Overview

Also called path traversal, this flaw lets an attacker supply ../ sequences to read or write files outside the web root.\nTargets include /etc/passwd, application configuration, source code and, combined with a write primitive, web shells.\nIt arises whenever a path is built by string concatenation instead of resolved and checked against a whitelist root.

Indicators of Compromise

Signals that suggest this is present on a system.

  • ../../ encoded in download parameters
  • Config or .env files downloadable
  • File-read errors that echo the requested path

Controls that stop it

  • Validate and Constrain All Input

    Treat every request as hostile. Reject anything that does not match an allow list, enforce type, length, range and format, and canonicalise before you validate so encoded bypasses cannot slip through. For file uploads, re-encode the image, randomise the name, strip metadata and store outside the web root on a domain that cannot execute code.

We use only the cookies needed to run this site — your session, your sign-in state and CSRF protection. There are no advertising or analytics trackers. How cookies are used