Path-Traversal
- Upload Issues
A cpio archive extraction allowed path traversal, which overwrote a user record to grant admin, and the admin page printed the flag.
- Arbitrary Code Execution via SCP Path Traversal in Cisco NDFC
Improper path validation in Cisco NDFC lets an authenticated, low-privileged attacker upload code via SCP path traversal and execute it with root privileges.
- SSFS
A file upload/download app whose /download/ endpoint had a plain path traversal, enough to read a flag off the filesystem.
- Unauthenticated Arbitrary File Read in Cisco NDFC (PnP)
The Out-of-Band Plug and Play feature of Cisco NDFC lets an unauthenticated, remote attacker read arbitrary files from the PnP container via improper path validation.
- Stray
A length check meant for single-character input was bypassed by passing the query parameter as an array, opening a path traversal to flag.txt.