πŸ›‘οΈ Security Lab Track A Β· Web Application Security Β· Stage 5

Track A Β· Stage 5

Web Application Security

Path Traversal / Local File Inclusion mediumnot started

A document viewer serves files by name from a templates directory, concatenating your input into a path. Traverse out of the directory to read a protected file containing the flag.

loading simulator…

Unrestricted File Upload β†’ RCE hardnot started

An avatar uploader accepts any file and stores it under a web-served, executable directory. Upload a script that the server will execute, and use it to read the flag.

loading simulator…