Skip to content
KitploitKITPLOIT
ToolsExploitsBlog
Log in
Submit
ToolsExploitsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

FeedsContactPrivacy© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories
servicenow — Scans ServiceNow instances for widget-simple-list plugin misconfigurations that expose data via the API, supporting single URLs, URL lists, fast-check, and proxy options. | Kitploit
Tools/GitHubGitHub/bsysop/servicenow
ReconnaissanceVulnerability ScannersData ExfiltrationInformation GatheringWeb SecurityPenetration TestingMisconfiguration
GitHubbsysop/servicenow

servicenow

Scans ServiceNow instances for widget-simple-list plugin misconfigurations that expose data via the API, supporting single URLs, URL lists, fast-check, and proxy options.

View Repository
66302 years agoReviewed by Kitploit

Most Popular

View all →

Discover the most used tools by our community.

Explore all tools

Browse our collection of tools

View all tools →
Share

ServiceNow Widget-Simple-List Misconfiguration Scanner

Overview

This tool scans for misconfigurations in the ServiceNow widget-simple-list plugin. It checks whether the target instance is vulnerable to data exposure risks due to misconfigured settings.

Important Note

For an in-depth understanding of the attack technique and exploitation, consult the technical details available here.

Pre-requisites

  • Python 3.x
  • Required Python libraries: requests

You can install the required libraries using pip:

pip install requests

Usage

  1. Clone the repository to your local machine.
  2. Navigate to the directory containing servicescan.py.
  3. Choose one of the following methods to run the script using Python 3:

Method 1: Single URL

python3 servicescan.py --url https://redacted.service-now.com

Method 2: Multiple URLs from a File

python3 servicescan.py --file urls.txt

Fast-Check Option

Perform a fast check that only scans for the table kb_knowledge using the --fast-check argument:

python3 servicescan.py --url https://redacted.service-now.com --fast-check

Using a Proxy

To use a proxy server, use the --proxy option:

python3 servicescan.py --url https://redacted.service-now.com --proxy http://host:port

Example Output

If the target instance is found to be vulnerable, you'll receive an output similar to the following:

https://redacted.service-now.com/api/now/sp/widget/widget-simple-list?t=incident is EXPOSED, found at least 167 items
https://redacted.service-now.com/api/now/sp/widget/widget-simple-list?t=oauth_entity is EXPOSED, found at least 3 items
Headers to forge requests:
X-UserToken: 76a458ffdbf5[REDACTED]0c02ba13393b764
Cookie: JSESSIONID=7EB7[REDACTED]B5D07E; glide_user_route=glide.4884750d[REDACTED]ca0436e4; glide_node_id_for_js=3143935013eaa5a1e[REDACTED]8a698b419c40837dfce63002d5;

Note: A table may be public but not necessarily expose sensitive information. Always verify that the disclosed data is indeed confidential before taking any action.

Credits and Contributors

  • Aaron Costello - Researcher who provided the technical details and exploitation method. Website
  • bsysop - Tool Creator
  • Aaron Ringo - Code Refactor and implementation of --proxy and --file implementations
  • Nathan Sanders - Filtering improvement to detect accurate leaking data
  • Daniel Müller - Implemented requests without the X-UserToken header.

Disclaimer

This tool is intended for educational and ethical testing purposes only. The authors are not responsible for any misuse or damage caused by this tool.

Download Tool