> For the complete documentation index, see [llms.txt](https://dev-angelist.gitbook.io/writeups-and-walkthroughs/llms.txt). Markdown versions of documentation pages are available by appending `.md` to page URLs; this page is available as [Markdown](https://dev-angelist.gitbook.io/writeups-and-walkthroughs/portswigger-web-security-academy/server-side-vulnerabilities/path-traversal/file-path-traversal-simple-case.md).

# File path traversal, simple case

## Description

This lab contains a path traversal vulnerability in the display of product images.

To solve the lab, retrieve the contents of the `/etc/passwd` file.

## Solution

<figure><img src="https://677614291-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FrRWtuMw6xkkeDjZfkcWC%2Fuploads%2FN6wXcCdgYpeIVc5ifs5N%2Fimage.png?alt=media&amp;token=c797db2b-7b37-475d-98d4-96977395851b" alt=""><figcaption></figcaption></figure>

Click to one of products shop: <https://0ac8007304f7f39b81adf85000a300b1.web-security-academy.net/product?productId=2>

<figure><img src="https://677614291-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FrRWtuMw6xkkeDjZfkcWC%2Fuploads%2F81vaEuZgnr4Z9Prg4l2T%2Fimage.png?alt=media&amp;token=56a62646-b423-49ad-acb5-1756e6911347" alt=""><figcaption></figcaption></figure>

The parameter productsID seems to not be vulnerable, than we can try to open the relative image, that usually is located into `/var/www/images` web server directory.

<https://0ac8007304f7f39b81adf85000a300b1.web-security-academy.net/image?filename=1.jpg>

<figure><img src="https://677614291-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FrRWtuMw6xkkeDjZfkcWC%2Fuploads%2FuMDs5BDvuOU8ICZM98YI%2Fimage.png?alt=media&amp;token=3acad14d-5428-432b-927f-2cc2fec9fb3b" alt=""><figcaption></figcaption></figure>

In this case directory and parameter are different, capturing it with Burp and trasfer to Repeater using CTRL+R

<figure><img src="https://677614291-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FrRWtuMw6xkkeDjZfkcWC%2Fuploads%2FxkQPxFk7MOFi1CMjKelz%2Fimage.png?alt=media&amp;token=e9ed3cef-78a6-4b73-a4bf-20d322725fc4" alt=""><figcaption></figcaption></figure>

Here, we can modify the filename reference adding `../../../../../etc/passwd` to do five jump back into directory, arriving to root `/` and accessing to `/etc/passwd` file:

<figure><img src="https://677614291-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FrRWtuMw6xkkeDjZfkcWC%2Fuploads%2FvMP051j5mC8HbX3nqxsY%2Fimage.png?alt=media&amp;token=a85422e3-c9ab-4bbf-8a51-f18ee816875e" alt=""><figcaption></figcaption></figure>

<figure><img src="https://677614291-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FrRWtuMw6xkkeDjZfkcWC%2Fuploads%2FmqOZyh9ZRM0pnnEGk1QO%2Fimage.png?alt=media&amp;token=eec8e24f-e906-43e9-9320-d1cee3f9ed5f" alt=""><figcaption></figcaption></figure>
