LFi local file inclusion directory to look in
one can insert file on server using this. any script with file from server can be vulnerable. we abuse the file location parameter
etc/issue
/etc/passwd
/etc/shadow
/etc/group
/etc/hosts
/etc/motd
/etc/mysql/my.cnf
/proc/[0-9]*/fd/[0-9]* (first number PID second is filedescriptor)
/proc/self/environ
/proc/version
/proc/cmdline
one can insert file on server using this. any script with file from server can be vulnerable. we abuse the file location parameter
etc/issue
/etc/passwd
/etc/shadow
/etc/group
/etc/hosts
/etc/motd
/etc/mysql/my.cnf
/proc/[0-9]*/fd/[0-9]* (first number PID second is filedescriptor)
/proc/self/environ
/proc/version
/proc/cmdline