SSCP Systems Security Certified PractitionerSystems and Application SecurityEasy

A penetration tester is evaluating a web application for common vulnerabilities. During the testing phase, they discover that by manipulating a parameter in the URL, they can force the application to display directory listings and even potentially access sensitive configuration files outside of the web root. Which of the following vulnerabilities has the penetration tester most likely identified?

  1. ADenial of Service (DoS)
  2. BCross-Site Request Forgery (CSRF)
  3. CPath Traversal
  4. DCross-Site Scripting (XSS)
Show answer & explanation

Correct answer: C. Path Traversal

Path traversal, also known as directory traversal, allows an attacker to access files and directories stored outside the web root folder by manipulating variables that reference files with "../" sequences.

Why the other options are wrong

  • A. DoS attacks aim to make a service unavailable to legitimate users, which is not indicated by accessing directory listings.
  • B. CSRF forces an end user to execute unwanted actions on a web application in which they're currently authenticated, which is not the scenario described.
  • D. XSS involves injecting malicious scripts into web pages viewed by other users, which is not described here.

Path Traversal

A web security vulnerability that allows an attacker to read arbitrary files on the server that is running an application, or to write arbitrary files to the server, by manipulating file paths.

  • Also known as directory traversal.
  • Exploits insufficient validation of user-supplied file paths.
  • Often uses '../' sequences to navigate directory structures.

Memory trick: Web paths lead to hidden files, if not secured tightly.

More Systems and Application Security questions