Skip to content
KitploitKITPLOIT
ToolsBlog
Submit
ToolsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories
Cisco-ASA-FTD-Web-Services-Traversal — CVE-2020-3452 - Cisco Adaptive Security Appliance (ASA) Software and Cisco Firepower Threat Defense (FTD) traversal | Kitploit
Tools/GitHubGitHub/fuzzlove/cisco-asa-ftd-web-services-traversal
Vulnerability AnalysisExploitationWeb Application ExploitationInformation GatheringPenetration Testing
GitHubfuzzlove/cisco-asa-ftd-web-services-traversal

Cisco-ASA-FTD-Web-Services-Traversal

CVE-2020-3452 - Cisco Adaptive Security Appliance (ASA) Software and Cisco Firepower Threat Defense (FTD) traversal

View Repository
6215 years agoNot yet reviewed

Most Popular

View all →

Discover the most used tools by our community.

Explore all tools

Browse our collection of tools

View all tools →
Share

Cisco Adaptive Security Appliance Software and Firepower Threat Defense Software Web Services Path Traversal Vulnerability

CVE-2020-3452

Usage: CVE-2020-3452.py https://target

Vulnerability description: A vulnerability in the web services interface of Cisco Adaptive Security Appliance (ASA) Software and Cisco Firepower Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to conduct directory traversal attacks and read sensitive files on a targeted system.

Sample output:

root@kitploit:~
➜  Cisco-ASA-FTD-Web-Services-Traversal git:(main) ✗ python CVE-2020-3452.py https://target
+-------------------------------------------------------------+

- [ Cisco ASA / FTD Web Services Traversal Vulnerability ]

-       -[ CVE-2020-3452 - PoC by: LiquidSky ^_^ ]-

+-------------------------------------------------------------+
[*] Checking potential target : https://target
[+] https://target is vulnerable... 
[+] Grabbing logo.gif from the host.
[+] https://target is vulnerable... 
[+] Grabbing http_auth.html from the host.
[+] https://target is vulnerable...
Download Tool