File Name Enumeration
Unknown
Vulnerability Details
Hi guys,
I am kind of surprised no one hast reported this issue yet.
(or maybe they have and due to the severity it was never patched?)
An example of this behavior would be:
https://hackerone.com//%5C../%5C../%5C../%5C../%5C../%5C../etc/passwd (which is a valid attempt even though we get an error saying file not found because..)
https://hackerone.com//%5C../%5C../%5C../%5C../%5C../%5C../etc/passwd_DOESNTEXIST will rediredt us to a 404 page.
Let me know if you need more info from my end.
Thanks,
Ben
Actions
View on HackerOneReport Stats
- Report ID: 33935
- State: Closed
- Substate: resolved
- Upvotes: 10