Certified Ethical Hacker (CEH v11) — Question 213
While testing a web application in development, you notice that the web server does not properly ignore the `dot dot slash` (../) character string and instead returns the file listing of a folder higher up in the folder structure of the server.
What kind of attack is possible in this scenario?
Answer options
- A. Cross-site scripting
- B. SQL injection
- C. Denial of service
- D. Directory traversal
Correct answer: D
Explanation
The correct answer is Directory traversal because the web server's inability to properly handle the `dot dot slash` input allows attackers to access files outside the intended directory. The other options, such as Cross-site scripting, SQL injection, and Denial of service, involve different vulnerabilities that do not pertain to file access through directory structure manipulation.