CompTIA Security+ (SY0-701)Threats, Vulnerabilities, and MitigationsMedium
A web server log shows repeated requests containing strings such as '../../../../etc/passwd' appended to a file-download parameter. Which type of vulnerability is being exploited?
- ADirectory traversal
- BCross-site scripting
- CRace condition
- DBuffer overflow
Show answer & explanationAnswer & explanation
Correct answer: A. Directory traversal
Directory traversal (path traversal) exploits insufficient input validation on file paths, allowing an attacker to use sequences like '../' to navigate outside the intended directory and access restricted files such as /etc/passwd.
Why the other options are wrong
- B. XSS injects scripts to run in a browser, unrelated to file path requests.
- C. A race condition exploits timing between checks and actions, not file path structure.
- D. Buffer overflow involves overwriting memory with oversized input, not path manipulation.
Directory Traversal
A vulnerability that allows attackers to access files and directories outside the intended web root by manipulating file path input.
- Uses '../' or encoded equivalents to escape restricted directories
- Mitigated by input sanitization and least-privilege file permissions
- Can expose sensitive OS files like /etc/passwd
Memory trick: Dots and slashes ('../') are the crowbar prying open forbidden folders.