Skip to content
KitploitKITPLOIT
ToolsBlog
Submit
ToolsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories
Tools/GitHubGitHub/dodiorne/cve-2022-31813
ReconnaissanceVulnerability ScannersExploitationWeb Application ExploitationInformation GatheringPenetration Testing
GitHubdodiorne/cve-2022-31813

cve-2022-31813

tester for cve-2022-31813

View Repository
111 year agoNot yet reviewed

Most Popular

View all →

Discover the most used tools by our community.

Explore all tools

Browse our collection of tools

View all tools →
Share
cve-2022-31813 — tester for cve-2022-31813 | Kitploit

CVE-2022-31813 Vulnerability Checker

Author: Derek Odiorne
GitHub: @dodiorne
Version: 1.2
Last Updated: May 21, 2025
MITRE ATT&CK Technique: T1190 – Exploit Public-Facing Application


🧠 Description

This tool is a black-box vulnerability scanner for detecting CVE-2022-31813, a path traversal and access control bypass vulnerability in Apache HTTP Server ≤ 2.4.53 using mod_proxy and ProxyPassMatch.

It is designed for penetration testers and red team operators who want a non-intrusive and observable method to detect this vulnerability without requiring access to server configurations.


🚀 Features

  • 🔍 Tests multiple bypass vectors using crafted HTTP requests
  • ✅ Provides clear vulnerability verdict per host
  • 🌈 Color-coded terminal output for fast interpretation
  • 🖼 Screenshots each request via headless browser for forensics
  • 📊 Logs all results into a structured CSV report
  • 🛡 MITRE ATT&CK reference included for operational reporting

🧪 Tested On

  • Python 3.8+
  • Debian / Ubuntu / Kali Linux
  • Google Chrome + ChromeDriver

Install Requirements

pip install requests selenium pandas --break-system-packages 🛠️ Ensure ChromeDriver is installed and in your PATH.

⚙️ Usage Scan a Single Host (port 80 by default)

python3 cve_2022_31813_checker.py -t example.com Scan a Host on a Specific Port

python3 cve_2022_31813_checker.py -t example.com --port 8080 Scan Multiple Hosts Create a targets.txt file:

example.com 192.168.1.10 web.server.org Then run:

python3 cve_2022_31813_checker.py -f targets.txt --port 8000 📁 Output After execution, you'll get a directory like:

cve_31813_output_20250521_153000/ ├── results.csv

└── screenshots/

root@kitploit:~
├── example_com_80__app_.._admin.png

├── ...

🚀 Example Usage The script supports scanning single or multiple hosts, using either HTTP or HTTPS, with automatic fallback detection for HTTPS redirection.

🔹 Scan a Single Target (Default: HTTP on port 80) python3 cve_2022_31813_checker.py -t example.com

🔹 Scan a Single Target on HTTPS (port 443) python3 cve_2022_31813_checker.py -t example.com --scheme https --port 443

🔹 Scan a Single Target on a Custom Port (e.g., 8080) python3 cve_2022_31813_checker.py -t example.com --port 8080

🔹 Scan Multiple Targets from a File Create a targets.txt file like: example.com 192.168.1.100 secure.company.org

python3 cve_2022_31813_checker.py -f targets.txt python3 cve_2022_31813_checker.py -f targets.txt --scheme https --port 443

Download Tool