File name/folder enumeration.

Disclosed: 2014-11-18 08:44:01 By nahamsec To factlink
Unknown
Vulnerability Details
Hello, an attacker may be able to map your server and find configuration file names by the following method: Valid attempt (Not found): https://staging.factlink.com/%5C../%5C../%5C../%5C../%5C../%5C../etc/passwd Invalid attempt (404) https://staging.factlink.com/%5C../%5C../%5C../%5C../%5C../%5C../etc/passwd_Nonexistant
Actions
View on HackerOne
Report Stats
  • Report ID: 35823
  • State: Closed
  • Substate: resolved
  • Upvotes: 3
Share this report