Skip to content
KitploitKITPLOIT
ToolsExploitsBlog
Log in
Submit
ToolsExploitsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories
CVE-2024-36991 — Proof-of-concept exploit for CVE-2024-36991 enabling arbitrary file read via path traversal in Splunk for Windows versions below 9.2.2, 9.1.5, and 9.0.10. | Kitploit
Tools/GitHubGitHub/gunzf0x/cve-2024-36991
Vulnerability AnalysisExploitationWeb Application ExploitationInformation GatheringPenetration Testing
GitHubgunzf0x/cve-2024-36991

CVE-2024-36991

Proof-of-concept exploit for CVE-2024-36991 enabling arbitrary file read via path traversal in Splunk for Windows versions below 9.2.2, 9.1.5, and 9.0.10.

View Repository
411 year agoNot yet reviewed

Most Popular

View all →

Discover the most used tools by our community.

Explore all tools

Browse our collection of tools

View all tools →
Share

CVE-2024-36991 - Splunk Path Traversal

Proof of Concept for CVE-2024-36991 which allows an attacker to read arbitrary files in Splunk for versions below to 9.2.2, 9.1.5, and 9.0.10 for Windows.

Usage

Read Splunk configuration files

To read Splunk files just run the script passing the target URL running Splunk and the configuration file you want to read. For example:

python3 CVE-2024-36991.py -u 'https://example.com:8000' -f '/etc/auth/splunk.secret'

Read Windows system files

To read Windows system files just add the flag --system-files. For example:

python3 CVE-2024-36991.py -u http://haze.htb:8000 -f '/Windows/System32/drivers/etc/hosts' --system-files

Always use this tool for good purposes. Be ethical (:

Download Tool