Forced Browsing
You can test if restricted resources are accessible leading to sensitive information exposure using a built-in word list. The following technologies are supported:
-
Apache
-
ColdFusion
-
Db
-
Django
-
Drupal
-
GraphQL
-
HashiCorp
-
J2ee
-
Jboss
-
Jenkins
-
Joomla
-
Laravel
-
lis
-
Nginx
-
Oracle
-
Reverse Proxy
-
SAP
-
SharePoint
-
Swagger
-
Tomcat
-
WordPress
You can also upload a custom word list.
Note: This feature is available only in the full scan mode.