From bb7e6b7cd0587903fc3040b3699f517fae02b2b0 Mon Sep 17 00:00:00 2001 From: Hi15358 Date: Tue, 29 Oct 2019 16:23:39 +0800 Subject: [PATCH] Update README.md --- Directory Traversal/README.md | 4 +++- 1 file changed, 3 insertions(+), 1 deletion(-) diff --git a/Directory Traversal/README.md b/Directory Traversal/README.md index 1420178..afa72bd 100644 --- a/Directory Traversal/README.md +++ b/Directory Traversal/README.md @@ -144,6 +144,8 @@ c:/unattend.txt c:/unattend.xml c:/unattended.txt c:/unattended.xml +c:/windows/repair/sam +c:/windows/repair/system ``` The following log files are controllable and can be included with an evil payload to achieve a command execution @@ -164,4 +166,4 @@ The following log files are controllable and can be included with an evil payloa ## References * [Directory traversal attack - Wikipedia](https://en.wikipedia.org/wiki/Directory_traversal_attack) -* [CWE-40: Path Traversal: '\\UNC\share\name\' (Windows UNC Share) - CWE Mitre - December 27, 2018](https://cwe.mitre.org/data/definitions/40.html) \ No newline at end of file +* [CWE-40: Path Traversal: '\\UNC\share\name\' (Windows UNC Share) - CWE Mitre - December 27, 2018](https://cwe.mitre.org/data/definitions/40.html)