Skip to content

Latest commit

 

History

History
16 lines (9 loc) · 397 Bytes

File metadata and controls

16 lines (9 loc) · 397 Bytes

#lab : File path traversal, traversal sequences stripped non-recursively

Use Burp Suite to intercept and modify a request that fetches a product image.

Modify the filename parameter, giving it the value:
....//....//....//etc/passwd
Observe that the response contains the contents of the /etc/passwd file.

payload

##result

result result