Skip to content
KitploitKITPLOIT
ToolsBlog
Submit
ToolsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories
ghostcat — Exploit tool for Apache Tomcat CVE-2020-1938 LFI vulnerability, enabling sensitive file reading and remote JSP payload execution via AJP connector. | Kitploit
Tools/GitHubGitHub/jptr218/ghostcat
Payload GenerationVulnerability AnalysisExploitationWeb Application ExploitationWeb Security
GitHubjptr218/ghostcat

ghostcat

Exploit tool for Apache Tomcat CVE-2020-1938 LFI vulnerability, enabling sensitive file reading and remote JSP payload execution via AJP connector.

View Repository
125 years agoNot yet reviewed

Most Popular

View all →

Discover the most used tools by our community.

Explore all tools

Browse our collection of tools

View all tools →
Share

This tool exploits an LFI vulnerability within Apache Tomcat named CVE-2020-1938 to not only view sensitive files, but also to run malicious JSP payloads.

It can be downloaded here (you will need to run it from the command line)

Usage:

ghostcat [target] [HTTP port] [AJP port] [file] [read/eval]
Download Tool