We will be covering the 6th lab for Directory Traversal for Portswigger Web Security Academy.
This lab contains a path traversal vulnerability in the display of product images.
The application validates that the supplied filename ends with the expected file extension.
To solve the lab, retrieve the contents of the /etc/passwd file.
--
Join along at Portswigger:
https://portswigger.net/web-security
Path Traversal Labs:
https://portswigger.net/web-security/...
More information on Path Traversal:
https://owasp.org/www-community/attac...
--
Feedback is welcome.
If you found value, please leave a sub and a like. Maybe share it?