Skip to content
KitploitKITPLOIT
ToolsExploitsBlog
Log in
Submit
ToolsExploitsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories
CVE-2025-5880 — PoC for a Path Traversal vulnerability in Whistle v2.9.98 via the /cgi-bin/sessions/get-temp-file endpoint. (Unpatched) | Kitploit
Tools/GitHubGitHub/ac8999/cve-2025-5880
Vulnerability AnalysisExploitationWeb Application Exploitation
GitHubac8999/cve-2025-5880

CVE-2025-5880

PoC for a Path Traversal vulnerability in Whistle v2.9.98 via the /cgi-bin/sessions/get-temp-file endpoint. (Unpatched)

View Repository
61 month agoNot yet reviewed

Most Popular

View all →

Discover the most used tools by our community.

Explore all tools

Browse our collection of tools

View all tools →
Share

Whistle 2.9.98 contains an unpatched path traversal vulnerability because the /cgi-bin/sessions/get-temp-file endpoint fails to adequately sanitize user input in the filename parameter. By supplying absolute paths or traversal sequences like /etc/passwd, an attacker can bypass directory restrictions and read sensitive system files directly from the underlying server.

POC for reading the /etc/passwd file

http://$target/cgi-bin/sessions/get-temp-file?filename=/etc/passwd

Description of image

Download Tool