webPromedium

Lab 156 — IntegraFlow — Path Traversal via Double URL Encoding

hackadvisor

Task: Express.js API integration platform serves documentation files via /api/resources/* endpoint with path traversal protection. Solution: double URL encoding (%252e%252e%252f) bypasses validation that checks raw URL but uses double-decoded params for file access, allowing arbitrary file read including /root/flag.txt.

$ ls tags/ techniques/
double_url_encoding_bypassvalidation_decode_mismatchsource_code_disclosureexpress_param_decoding

🔒

Permission denied (requires tier.pro)

Sign in to access full writeups

Sign in with GitHub to continue. No email required.

$sign in

$ grep --similar

Similar writeups