SecLists/Discovery/Web-Content/Web-Servers/Apache-Tomcat.txt
0xBassia 5693fbea36
feat(wordlist): Add wordlists for: Kubernetes, Docker, Elasticsearch, Grafana, GitLab, Prometheus (PR #1293)
This also added some more payloads to the wordlists for Tomcat, NginX and Hashicorp-consul.

Co-authored-by: PentesterTN <pentestertn@proton.me>
2026-03-23 02:46:06 -03:00

145 lines
3.5 KiB
Text

META-INF
META-INF/
META-INF/context.xml
RELEASE-NOTES.txt
ROOT
RUNNING.txt
WEB-INF
WEB-INF/
WEB-INF/classes/
WEB-INF/web.xml
add
balancer
conf/
conf/server.xml/
dav
deploy
docs
docs/
docs/api
docs/config
docs/setup
examples
examples/%252e%252e/manager/html
examples/%2e%2e/manager/html
examples/../manager/html
examples/jsp/index.html
examples/jsp/snp/snoop.jsp
examples/jsp/source.jsp
examples/servlet/HelloWorldExample
examples/servlet/SnoopServlet
examples/servlet/TroubleShooter
examples/servlet/default/jsp/snp/snoop.jsp
examples/servlet/default/jsp/source.jsp
examples/servlet/org.apache.catalina.INVOKER.HelloWorldExample
examples/servlet/org.apache.catalina.INVOKER.SnoopServlet
examples/servlet/org.apache.catalina.INVOKER.TroubleShooter
examples/servlet/org.apache.catalina.servlets.DefaultServlet/jsp/snp/snoop.jsp
examples/servlet/org.apache.catalina.servlets.DefaultServlet/jsp/source.jsp
examples/servlet/org.apache.catalina.servlets.WebdavServlet/jsp/snp/snoop.jsp
examples/servlet/org.apache.catalina.servlets.WebdavServlet/jsp/source.jsp
examples/servlet/snoop
examples/servlets/index.html
examples/websocket
examples/websocket/index.xhtml
host-manager
host-manager/
host-manager/add
host-manager/host-manager.xml
host-manager/html
host-manager/html/*
host-manager/list
host-manager/remove
host-manager/start
host-manager/stop
host-manager/text
host-manager/text/list
html/*
install
j4p
j_security_check?j_username=admin&j_password=admin
j_security_check?j_username=manager&j_password=manager
j_security_check?j_username=tomcat&j_password=tomcat
jmxproxy/*
jolokia
jolokia/
jolokia/exec/java.lang:type=Threading/dumpAllThreads/true/true
jolokia/list
jolokia/read/java.lang:type=Memory
jolokia/read/java.lang:type=Runtime/ClassPath
jolokia/version
jsp-examples
list
manager
manager/deploy
manager/deploy?path=foo
manager/html
manager/html/
manager/html/*
manager/install
manager/jmxproxy
manager/jmxproxy/*
manager/jmxproxy/?get=java.lang:type=Memory&att=HeapMemoryUsage
manager/jmxproxy/?get=java.lang:type=Runtime&att=ClassPath
manager/list
manager/manager.xml
manager/reload
manager/remove
manager/resources
manager/roles
manager/save
manager/serverinfo
manager/sessions
manager/start
manager/status
manager/status.xsd
manager/status/*
manager/status/all
manager/status?XML=true
manager/stop
manager/text
manager/text/serverinfo
manager/text/sessions?path=/
manager/text/sslConnectorCiphers
manager/text/threaddump
manager/undeploy
probe
probe/
psi-probe
psi-probe/
reload
remove
resources
roles
save
server-info
server-status
serverinfo
servlet/default
servlet/default/
servlet/mstrWebAdmin
servlet/org.apache.catalina.INVOKER.org.apache.catalina.servlets.DefaultServlet/tomcat.gif
servlet/org.apache.catalina.INVOKER.org.apache.catalina.servlets.SnoopAllServlet
servlet/org.apache.catalina.INVOKER.org.apache.catalina.servlets.WebdavServlet/
servlet/org.apache.catalina.servlets.DefaultServlet/
servlet/org.apache.catalina.servlets.DefaultServlet/tomcat.gif
servlet/org.apache.catalina.servlets.HTMLManagerServlet
servlet/org.apache.catalina.servlets.InvokerServlet/org.apache.catalina.servlets.DefaultServlet/tomcat.gif
servlet/org.apache.catalina.servlets.InvokerServlet/org.apache.catalina.servlets.SnoopAllServlet
servlet/org.apache.catalina.servlets.ManagerServlet
servlet/org.apache.catalina.servlets.SnoopAllServlet
servlet/org.apache.catalina.servlets.WebdavServlet/
servlets-examples
sessions
shared/
shared/lib/
start
status.xsd
status/*
stop
tomcat-docs
undeploy
webdav
webdav/index.html
webdav/servlet/org.apache.catalina.servlets.WebdavServlet/
webdav/servlet/webdav/