-include-..-2F..-2F..-2F..-2Froot-2F

-include-..-2f..-2f..-2f..-2froot-2f »

Phiewer PRO makes managing, viewing, and editing photos, RAW images, and videos faster and easier on Mac.

Pay once. Use forever.

What our users say

Reviews from the App Store

starstarstarstarstar

Fast, simple – excellent!

Just downloaded and loaded 500 images in 2 seconds. The slideshow function with various settings and fullscreen view is also a real plus. Replaced Pixea on my computer. After the recent update in January 2026, a real recommendation for me. -include-..-2F..-2F..-2F..-2Froot-2F

Felix theCat

starstarstarstarstar

perfect!

Perfect program to view and edit images. Extremely affordable price. Tried many others, Phiewer pro is outstanding!! If this payload is successful, the consequences can

pyPeter01

starstarstarstarstar

Photo viewer that leaves no wish unfulfilled

It has already replaced Preview as my default photos viewer. Lightweight and battery-saving with an integrated photo editor, which is really impressive with its features for quick editing. As a teacher I use the app for academic purposes. Easy to use, self-explanatory, many functions, extensive options to design the way you want to see your photos! Friendly support team. Parameter Confusion :

Man.Osm

#1 in the Photo & Video Charts on the Apple App Store in Germany, March 2026.

Featured on iFun.de

Buy once, use forever.

No subscription. Perfect for creatives & power users.

Phiewer PRO Mac photo viewer main window
Phiewer PRO gallery view for macOS
Phiewer PRO image editing filters on macOS
Phiewer PRO RAW image viewer for Mac
Phiewer PRO file management on macOS
Phiewer PRO Exposé gallery view
Phiewer PRO batch export and compression
Phiewer PRO Finder tags integration
Phiewer PRO pinboard view Mac
Phiewer PRO EXIF data viewer macOS

If this payload is successful, the consequences can be severe:

http://vulnerable.site/index.php?include=-include-..-2F..-2F..-2F..-2Froot-2Fetc-2Fpasswd

If successful, the web application reads and returns: /root/etc/passwd (unlikely) or /root/.bashrc or attempts to include a malicious file from /root/uploaded.txt.

Let’s break this string down methodically.

The /root directory, particularly in Linux systems, is the home directory for the root user. Files and directories within /root are critical for system administration and security.

Remove .., ./, %2F, %5C, and obfuscated variants like -2F:

$input = str_replace(['..', '-2F', '%2F', '\\'], '', $_GET['path']);
  • Parameter Confusion:

  • Deep Traversal:

  • This is a Local File Inclusion (LFI) attack with encoding obfuscation.

    Supported Formats

    Over 80 file formats, from standard images to professional RAW formats.

    -include-..-2F..-2F..-2F..-2Froot-2F

    Images

    PNGJPGJPEGBMPGIFTIFFTIFHEICHEIFWebPICNSAVIFTGAEXRHDRPBMPGMPPMSGIMPO
    PDFPSDEPSSVGICOJP2JPXPICT
    RAW format support icon

    RAW

    3FRARIARWBAYCAPCR2CR3CRWDCRDCSDNGDRFEIPERFFFFHIFIIQK25KDCMEFMOSMRWNEFNRWOBMORFPEFPTXPXNR3DRAFRAWRWLRW2RWZSR2SRFSRWX3F
    -include-..-2F..-2F..-2F..-2Froot-2F

    Videos & Audio

    MP4MOVM4VM4AAVIMPGMPEG3GP3G2QTMTSM2TSTS
    MP3WAVAIFFAIFAACCAFAC3FLAC

    -include-..-2f..-2f..-2f..-2froot-2f »

    If this payload is successful, the consequences can be severe:

    http://vulnerable.site/index.php?include=-include-..-2F..-2F..-2F..-2Froot-2Fetc-2Fpasswd

    If successful, the web application reads and returns: /root/etc/passwd (unlikely) or /root/.bashrc or attempts to include a malicious file from /root/uploaded.txt.

    Let’s break this string down methodically.

    The /root directory, particularly in Linux systems, is the home directory for the root user. Files and directories within /root are critical for system administration and security.

    Remove .., ./, %2F, %5C, and obfuscated variants like -2F:

    $input = str_replace(['..', '-2F', '%2F', '\\'], '', $_GET['path']);
    
  • Parameter Confusion:

  • Deep Traversal:

  • This is a Local File Inclusion (LFI) attack with encoding obfuscation.

    Ready to get started?

    Download Phiewer PRO and experience a fast, reliable, and professional media viewer for Mac.

    Requires macOS 15.0 or later