Back to directory
WRITEUP #995

Hunting for Nginx Alias Traversals in the wild

OtherPath traversal
by@c3l3si4n(Daniel (Celesian) Matsumoto)
Bounty
6,500
Program
BitwardenGoogle
Published
Jul 3, 2023
Added to HackDex
Jul 4, 2023
Read Full Writeuphttps://labs.hakaioffsec.com/nginx-alias-traversal/
RELATED WRITEUPS
Oracle Retail Xstore Suite: Pre-authenticated Path Traversal
OtherPath traversal
Securing Developer Tools: Unpatched Code Vulnerabilities in Gogs (2/2)
OtherPath traversal
Data Theft in Salesforce: Manipulating Public Links
OtherSOQL injection
Directory Traversal, SQL Injection and Server-Side Request Forgery
SQL InjectionPath traversal
When Certificates Fail: A Story of Bypassed MFA in Remote Access
Other2FA / MFA bypass

Built with ❤️ by Shubham Rawat