Path Traversal with rawurldecode and dots validation
I’m trying to check if it’s possible to bypass a two dots verification to perform a Path Traversal, downloading files out of the allowed folder. The problem is that it uses rawurldecode when validating the submitted file, so URL Encoding t… Continue reading Path Traversal with rawurldecode and dots validation