@i0null last time I reported a path traversal two things happened:

  • they added a check for ../. They should have used realpath, but I could not find another way to get the vuln to work, even URL encoding, so that's fine for me.
  • they said they would interview me for a job offer, I'm still waiting this interview years later
  • @qgustavor @i0null regarding the 2. point:

    The company in question has probably more problems than you would like to work with so that's a bullet dodged.

    @ppxl @i0null I guess I dodged a bullet exiting from the last company I was in...