
tester for cve-2022-31813
Author: Derek Odiorne
GitHub: @dodiorne
Version: 1.2
Last Updated: May 21, 2025
MITRE ATT&CK Technique: T1190 – Exploit Public-Facing Application
This tool is a black-box vulnerability scanner for detecting CVE-2022-31813, a path traversal and access control bypass vulnerability in Apache HTTP Server ≤ 2.4.53 using mod_proxy and ProxyPassMatch.
It is designed for penetration testers and red team operators who want a non-intrusive and observable method to detect this vulnerability without requiring access to server configurations.
pip install requests selenium pandas --break-system-packages 🛠️ Ensure ChromeDriver is installed and in your PATH.
⚙️ Usage Scan a Single Host (port 80 by default)
python3 cve_2022_31813_checker.py -t example.com Scan a Host on a Specific Port
python3 cve_2022_31813_checker.py -t example.com --port 8080 Scan Multiple Hosts Create a targets.txt file:
example.com 192.168.1.10 web.server.org Then run:
python3 cve_2022_31813_checker.py -f targets.txt --port 8000 📁 Output After execution, you'll get a directory like:
cve_31813_output_20250521_153000/ ├── results.csv
└── screenshots/
├── example_com_80__app_.._admin.png
├── ...
🚀 Example Usage The script supports scanning single or multiple hosts, using either HTTP or HTTPS, with automatic fallback detection for HTTPS redirection.
🔹 Scan a Single Target (Default: HTTP on port 80) python3 cve_2022_31813_checker.py -t example.com
🔹 Scan a Single Target on HTTPS (port 443) python3 cve_2022_31813_checker.py -t example.com --scheme https --port 443
🔹 Scan a Single Target on a Custom Port (e.g., 8080) python3 cve_2022_31813_checker.py -t example.com --port 8080
🔹 Scan Multiple Targets from a File Create a targets.txt file like: example.com 192.168.1.100 secure.company.org
python3 cve_2022_31813_checker.py -f targets.txt python3 cve_2022_31813_checker.py -f targets.txt --scheme https --port 443