File Name Enumeration

Disclosed: 2014-11-17 22:28:55 By nahamsec To security
Unknown
Vulnerability Details
Hi guys, I am kind of surprised no one hast reported this issue yet. (or maybe they have and due to the severity it was never patched?) An example of this behavior would be: https://hackerone.com//%5C../%5C../%5C../%5C../%5C../%5C../etc/passwd (which is a valid attempt even though we get an error saying file not found because..) https://hackerone.com//%5C../%5C../%5C../%5C../%5C../%5C../etc/passwd_DOESNTEXIST will rediredt us to a 404 page. Let me know if you need more info from my end. Thanks, Ben
Actions
View on HackerOne
Report Stats
  • Report ID: 33935
  • State: Closed
  • Substate: resolved
  • Upvotes: 10
Share this report