Quiz 5 Question 8 of 20

A penetration tester discovers a web application with the following URL: https://app.example.com/report?file=../../../etc/passwd. Testing this URL returns the contents of /etc/passwd. Which vulnerability class is this, and what is the appropriate next step in a black-box test?

Select an answer to reveal the explanation.

Motivation