Web Hack List

Collected research

Write-up for a Path Traversal on Gravitee.io

Write-up of Path Traversal on Gravitee.io

Gravitee.io embedded every img src of an outgoing HTML mail as a CID attachment, reading the path straight from the tag with no validation. HTML injection into the unauthenticated registration form name fields let an attacker point that tag at ../../../etc/passwd and receive arbitrary server files as an email attachment.

Record

Document
Write-up of Path Traversal on Gravitee.io
Researcher
Maxime Escourbiac and @Fisjkars
Published by
Medium
Date
Topic
Server

In the archive

Tags

This page is the archive's own catalogue record. The research is the work of Maxime Escourbiac and @Fisjkars, first published at the original source. Preserved copies are kept so the citation survives its host; this one was last captured on .