Path traversal escapes the intended file area
If a filename comes from the user and is used to open a file, the user can name a file somewhere else.
Sequences that climb out of the intended directory reach configuration, credentials and system files. It is one of the oldest flaws there is and it survives because building a path from user input is the obvious way to do it. Resolve and check the final path rather than filtering the input.
More on Web application security
- CSRF abuses an authenticated browserTheir note, your session
- XSS turns trusted pages into script deliveryIt comes out in your own voice
- Output encoding is context-specificThe plug has to match the socket
- File upload security is more than extension checkingThe label is a claim, not a check
- Open redirects lend trusted domains to phishingYour livery, their destination
- Security headers shape browser behaviourInstructions the browser follows
