Python3

Absolute Path Traversal

drag_indicator
info
drag_indicator
inputs
drag_indicator
inspect

Absolute path traversal

Found a way to escape the /tmp/files/notes/ directory and access arbitary files on the vulnerable application!

Goal

Capture the flag! The flag can be found in the file: /tmp/secret/flag.txt

Hints

Solution

drag_indicator
waf
INPUT
OUTPUT
drag_indicator
code
drag_indicator
result