Path traversal escapes the intended file area

If a filename comes from the user and is used to open a file, the user can name a file somewhere else.

Sequences that climb out of the intended directory reach configuration, credentials and system files. It is one of the oldest flaws there is and it survives because building a path from user input is the obvious way to do it. Resolve and check the final path rather than filtering the input.

More on Web application security