๐Ÿงช Lab Info

๐Ÿ” Vulnerability:

This lab contains a path traversal vulnerability in the display of product images.

๐ŸŽฏ Goal:

To solve the lab, retrieve the contents of the /etc/passwd file.


๐Ÿชœ Steps to Solve

  1. ๐Ÿ›๏ธ Open the lab and go to any product page.
  2. ๐Ÿ” Click on "View details" of the product.
  3. ๐Ÿ–ฑ๏ธ Right-click on the product image and choose "Open image in new tab".
  4. ๐Ÿ”— Observe the image URL, which will look like

๐Ÿ•ต๐Ÿป Let's Exploit It

๐Ÿ’ก We're going to perform a directory traversal by modifying the filename parameter

<https://0a3c008f046c45dc804367ba00460059.web-security-academy.net/image?filename=../../../etc/passwd>

Like this and it will give us

image.png

and return to the lab it will be solved

Congrats u solved the lab ๐ŸŽ‰