Tagged articles

path traversal

9 articles · Page 1 of 1
Black & White Path
Black & White Path
Aug 10, 2026 · Information Security

CVE-2026-45454: SharePoint Server Upload.aspx Path Traversal Leads to Remote Code Execution

The AretiQ security team disclosed a path‑traversal flaw in SharePoint Server's Upload.aspx page that lets an authenticated user with Contribute rights upload files to any library, and when PageParserPaths permits server‑side scripts, an ASPX webshell can be executed for full remote code execution, with CVSS 3.1 score 6.5 (Microsoft 8.2).

CVE-2026-45454PowerShellRemote Code Execution
0 likes · 14 min read
CVE-2026-45454: SharePoint Server Upload.aspx Path Traversal Leads to Remote Code Execution
CTO Full-Stack Academy
CTO Full-Stack Academy
Jul 22, 2026 · Information Security

Understanding Path Traversal: How Directory Traversal Leads to Arbitrary File Reads

The article explains how unsanitized user‑supplied filenames combined with simple path concatenation enable attackers to traverse directories and read arbitrary files, illustrates common vulnerable endpoints with Java examples, and outlines prioritized defenses such as ID whitelisting and canonical path validation.

Web Securitydirectory traversalfile read
0 likes · 7 min read
Understanding Path Traversal: How Directory Traversal Leads to Arbitrary File Reads
Black & White Path
Black & White Path
Jun 16, 2026 · Information Security

Testing MCP Servers for Security Vulnerabilities with Mcpwn

This guide explains how to install the Mcpwn tool, understand its detection methods for RCE, path traversal, and prompt injection, and run both quick and focused scans against public and custom MCP servers to uncover critical security flaws.

AI securityMCPMcpwn
0 likes · 6 min read
Testing MCP Servers for Security Vulnerabilities with Mcpwn
Black & White Path
Black & White Path
Feb 14, 2026 · Information Security

How I Uncovered Critical Vulnerabilities in an EDU Certificate Site

The author details a step‑by‑step security assessment of an EDU certificate platform, revealing edge asset discovery, unauthorized .map file leakage, arbitrary file download and upload, path‑traversal flaws, and credential exposure via Bash history, culminating in high‑severity findings.

EDU certificate sitearbitrary file uploadbash history credential leakage
0 likes · 5 min read
How I Uncovered Critical Vulnerabilities in an EDU Certificate Site
IT Services Circle
IT Services Circle
Sep 29, 2025 · Backend Development

How Go’s New os.Root API Stops Path Traversal Attacks

This article explains the severe risks of file‑path traversal attacks in Go applications, reviews common exploitation techniques, evaluates existing mitigation methods, and demonstrates how the newly introduced os.Root API provides a robust, native solution for securely handling user‑supplied file paths.

File Handlingos.Rootpath traversal
0 likes · 15 min read
How Go’s New os.Root API Stops Path Traversal Attacks
Laravel Tech Community
Laravel Tech Community
Sep 20, 2022 · Information Security

Path Traversal Vulnerability in Go net/url (CVE-2022-32190)

The Go net/url package contains a path traversal flaw (CVE-2022-32190) where JoinPath fails to strip "../" segments, allowing attackers to access sensitive files, affecting versions prior to 1.18.6 and 1.19.1, and can be mitigated by upgrading to the patched releases.

CVE-2022-32190Vulnerabilitynet/url
0 likes · 3 min read
Path Traversal Vulnerability in Go net/url (CVE-2022-32190)
System Architect Go
System Architect Go
Mar 1, 2021 · Information Security

How Attackers Exploit Directory Traversal and How to Defend Against It

This article explains what directory (path) traversal is, demonstrates how attackers can read or write arbitrary files on a server by manipulating file‑path parameters, outlines common bypass techniques, and provides concrete defensive coding practices to mitigate the vulnerability.

VulnerabilityWeb Securitydefense
0 likes · 6 min read
How Attackers Exploit Directory Traversal and How to Defend Against It