Skip to content

jptr218/ghostcat

Folders and files

NameName
Last commit message
Last commit date

Latest commit

 

History

7 Commits
 
 
 
 
 
 

Repository files navigation

This tool exploits an LFI vulnerability within Apache Tomcat named CVE-2020-1938 to not only view sensitive files, but also to run malicious JSP payloads.

It can be downloaded here (you will need to run it from the command line)

Usage:

ghostcat [target] [HTTP port] [AJP port] [file] [read/eval]

About

An implementation of CVE-2020-1938

Resources

Stars

Watchers

Forks

Releases

No releases published

Packages

No packages published

Languages