Skip to content
KitploitKITPLOIT
أدواتالمدونة
إرسال
أدواتالمدونة
إرسال

أدوات الاختراق واختبار الاختراق والأمن السيبراني لترسانتك الأمنية!

Kitploit هو دليل لأدوات الاختراق والأمن السيبراني واختبار الاختراق. اكتشف آخر تحديثات المشاريع للعثور على الثغرات وتحليل الأنظمة وأتمتة الاختبارات وتعزيز أمنك.

··الخلاصات·اتصال·الخصوصية·© 2026 Kitploit

دليل الأدوات

الفئات

عرض جميع الفئات
Loading categories
CVE-2020-3452_Cisco_ASA_PathTraversal — برنامج إثبات المفهوم لـ CVE-2020-3452 — ثغرة اجتياز المسار في Cisco ASA/FTD. يدعم الاستخراج التلقائي لأهداف الملفات المعروفة مع حد أقصى لعدد التنزيلات الناجحة للسلامة. مخصص فقط لاختبار الأمان والبحث المصرح بهما. | Kitploit
أدوات/GitHubGitHub/abrewer251/cve-2020-3452_cisco_asa_pathtraversal
تحليل الثغرات الأمنيةالاستغلالاستغلال تطبيقات الويبجمع المعلوماتاختبار الاختراقالتعلم والتعليم
GitHubabrewer251/cve-2020-3452_cisco_asa_pathtraversal

CVE-2020-3452_Cisco_ASA_PathTraversal

برنامج إثبات المفهوم لـ CVE-2020-3452 — ثغرة اجتياز المسار في Cisco ASA/FTD. يدعم الاستخراج التلقائي لأهداف الملفات المعروفة مع حد أقصى لعدد التنزيلات الناجحة للسلامة. مخصص فقط لاختبار الأمان والبحث المصرح بهما.

الأكثر شعبية

عرض الكل →

اكتشف الأدوات الأكثر استخدامًا من قبل مجتمعنا.

استكشف جميع الأدوات

تصفح مجموعتنا من الأدوات

عرض جميع الأدوات →
مشاركة
عرض المستودع
منذ 11 أشهرلم تتم المراجعة بعد

CVE-2020-3452_Cisco_ASA_PathTraversal

نص برهان المفهوم لـ CVE-2020-3452 — ثغرة اجتياز المسار في Cisco ASA/FTD. يدعم الاستخراج الآلي للملفات المستهدفة المعروفة بحد أقصى صارم لعمليات التنزيل الناجحة حفاظاً على السلامة. مخصص لاختبار الأمان المصرح به وأغراض البحث فقط.


🔐 وصف مستودع GitHub

نص برهان المفهوم لـ CVE-2020-3452 — ثغرة اجتياز المسار في Cisco ASA/FTD. يدعم الاستخراج الآلي للملفات المستهدفة المعروفة بحد أقصى صارم لعمليات التنزيل الناجحة حفاظاً على السلامة. مخصص لاختبار الأمان المصرح به وأغراض البحث فقط.


📄 README.md

root@kitploit:~
# CVE-2020-3452 PoC — Cisco ASA/FTD Path Traversal

This is a modified proof-of-concept exploit script for [CVE-2020-3452](https://nvd.nist.gov/vuln/detail/CVE-2020-3452), a directory traversal vulnerability affecting Cisco ASA and FTD devices.

The vulnerability allows unauthenticated, remote attackers to **read arbitrary files** on affected systems via a crafted HTTP request. This script automates that process by attempting to retrieve a predefined list of common configuration, portal, and HTML files, and stores successful responses locally.

> **⚠️ For authorized testing and research only. Use responsibly.**

---

## ✅ Features

- 🔁 Iterates through a curated list of target file paths known to exist on ASA/FTD systems.
- ✅ Only writes responses with **HTTP 200** and **non-empty content**.
- 🧮 Stops automatically after **200 successful downloads** to prevent abuse or noise.
- 🗂️ Writes all files to an `output/` directory, creating it automatically.
- 🔒 Sanitizes all output filenames to prevent accidental traversal or injection.
- 🧼 Suppresses SSL warnings (ASA certs are often self-signed).

---

## 🖥️ Usage

```bash
# Install dependencies
pip install requests

# Run the script
python3 cve_2020_3452.py <target-host>
```

Example:

```bash
python3 cve_2020_3452.py firewall.example.com
```

All successful files will be saved to the `output/` folder.

You may also run the script interactively:

```bash
python3 cve_2020_3452.py
```

---

## 🔧 Configuration

| Variable             | Description                                                           |
| -------------------- | --------------------------------------------------------------------- |
| `MAX_SUCCESS_WRITES` | Stops script after this number of HTTP 200 file saves (default: 200). |
| `OUTPUT_DIR`         | Directory where files will be written (default: `output/`).           |

You can safely edit these at the top of the script.

---

## 📚 Background

* **CVE**: [CVE-2020-3452](https://nvd.nist.gov/vuln/detail/CVE-2020-3452)
* **Affected**:

  * Cisco ASA: 9.6 – 9.14.1.10
  * Cisco FTD: 6.2.3 – 6.6.0.1
* **Impact**: Allows unauthenticated file disclosure via crafted URL traversal.

---

## ⚠️ Legal & Ethical Notice

This script is provided **for educational and authorized security research purposes only**.

* 🛑 **Do NOT use** this tool on systems you do not own or explicitly have permission to test.
* 🧑‍⚖️ Unauthorized use may be illegal and unethical under local, federal, or international law.
* 🤝 You assume all responsibility for use of this tool.

---

## 🙏 Credits

* Original author: [@freakyclown](https://github.com/cygenta)
* Modifications: hard-coded success limit, file hygiene, output directory isolation

---

## 📜 License

MIT License — see [`LICENSE`](https://github.com/abrewer251/cve-2020-3452_cisco_asa_pathtraversal/blob/HEAD/LICENSE) for details.


📦 requirements.txt

قم بتضمين هذا في مستودعك لتسهيل الإعداد:

root@kitploit:~
requests

📜 LICENSE (MIT)

root@kitploit:~
MIT License

Copyright (c) 2025

Permission is hereby granted, free of charge, to any person obtaining a copy
of this software and associated documentation files (the "Software"), to deal
in the Software without restriction...


تنزيل الأداة