Arbitrary local file read via file upload

Description

Acunetix WVS uploaded a ZIP file containing a symlink to /etc/passwd. It looks like that web application processed this file and returned the contents of /etc/passwd in response.

Remediation

The web application should filter symlinks included inside ZIP files.

References