Skip to content
Vulnerability field guide

Path Traversal

Path traversal lets an attacker climb out of an intended directory with dot-dot-slash sequences and read arbitrary files on the server. Here is how it works, the encodings that defeat naive filters, and the canonicalization fix that stops it.

3 articles 14 min total Overview to advanced techniques