There are 1 repository under path-traversal topic.
Check your WAF before an attacker does
File Inclusion & Directory Traversal fuzzing, enumeration & exploitation tool.
Burp extension to detect alias traversal via NGINX misconfiguration at scale.
A phased, evasive Path Traversal + LFI scanning & exploitation tool in Python
Zen protects your Node app against attacks with one line of code. Get peace of mind— at runtime.
Zen protects your Java app against attacks with one line of code. Get peace of mind— at runtime.
Simple machine learning based web application firewall (WAF) created in python
Burpsuite Plugin to detect Directory Traversal vulnerabilities
μετάμάσκα - malevolent payload classifier
Fast Path Traversal exploitation tool
Dump files via Directory Traversal, LFI, Arbitrary File Read in a breeze with the help of ffuf
An API for escaping different kind of queries
Path Traversal On The "/Modules/Messaging/" Endpoint In Splunk Enterprise On Windows
POC for CVE-2021-34429 - Eclipse Jetty 11.0.5 Sensitive File Disclosure
🤨🔎 A simple path traversal checker made with Rust. Useful for APIs that serve dynamic files.
A powerful WAF (HTTP 403/401) and URL parser bypass tool developed in Go, designed to preserve exact URL paths and structures during testing.
LFI2Keys automates the process of extracting user accounts from /etc/passwd and attempts to locate private SSH keys through LFI
GoBypass403 is a tool designed to help security professionals test and bypass 403 Forbidden errors on web applications. It streamlines the penetration testing process, making it easier to identify vulnerabilities and enhance web security. 🛠️💻
Perform With Shell Scanner Using Path Traversal & Strings
Proof of Concept for CVE-2024-36991. Path traversal for Splunk versions below 9.2.2, 9.1.5, and 9.0.10 for Windows which allows arbitrary file read.
Exploit CVE-2020-29134 - TOTVS Fluig Platform - Path Traversal
OpenEMR < 5.0.2 - (Authenticated) Path Traversal - Local File Disclosure
CVE-2021-41773: Path Traversal Zero-Day in Apache HTTP Server Exploited
Mobile Security Framework is an intelligent, all-in-one open source mobile application (Android/iOS/Windows) automated pen-testing framework capable of performing static, dynamic analysis and web API testing.
WAFManis is a Protocol-Level WAF Evasion Fuzzing Tool that automates the discovery of evasion vulnerabilities in Web Application Firewalls (WAFs) by fuzzing HTTP requests to identify potential bypass techniques.
Bash script to automate Local File Inclusion (LFI) attacks on aiohttp server version 3.9.1.
Replication package of the paper 'Large Language Models for In-File Vulnerability Localization are "Lost in the End"' (https://doi.org/10.1145/3715758)
A powerful, multi-threaded scanner designed for bug bounty hunters and penetration testers to detect exposed or sensitive paths hidden via robots.txt. Supports HTTP/2, advanced 401/403 bypass techniques, multiple HTTP methods, and outputs in JSON/CSV formats.