Path Traversal

Exploit path traversal and local/remote file inclusion (LFI/RFI) via URL parameters, cookies, and hidden fields using ../ sequences, URL encoding (%2e%2e%2f), double encoding (%252e%252e%255c), Unicode bypasses (..%c0%af), and Windows UNC paths. PHP include/require with $_GET/$_POST/$_COOKIE pattern. Target /etc/passwd, boot.ini, web.config. Tools: DotDotPwn, WFuzz, Burp Suite, ZAP.

ShulkwiSEC Updated 21 repo stars

File contents

ShulkwiSEC/bb-huge/tree/main/skills/curated/path-traversal commit af5544baa8

Frequently asked questions

npx skillmds@latest add shulkwisec/path-traversal