HTTP file servers that build a filesystem path from user input and fail to normalize it allow traversal out of the served root. Sequences like ../, their encoded forms, and absolute paths reach files elsewhere on the host, turning the file server into arbitrary file read. This overlaps the web path-traversal class, applied to the file-serving feature.
curl --path-as-is 'http://<target>/download?file=../../../../etc/passwd'
curl --path-as-is 'http://<target>/..%2f..%2f..%2fetc%2fpasswd' # encoded
Exploitation notes#
- Try raw, URL-encoded, double-encoded, and overlong UTF-8 traversal sequences, since filters often catch only the literal
../. - On Windows file servers, use
..\and target known config and credential files. - The deeper treatment of traversal and its bypasses lives in the Web area; this is the file-server-specific application.