SecLists/Discovery/Web-Content/CMS
2025-02-21 20:30:29 -03:00
..
trickest-cms-wordlist [Github Action] Automated trickest wordlists update. 2025-01-24 10:04:19 +00:00
Adobe-AEM_2021.txt fix(docs): Moved 'aem2.txt' into the CMS directory 2025-02-21 20:30:29 -03:00
AdobeCQ-AEM_2017.txt fix(docs): Moved 'aem2.txt' into the CMS directory 2025-02-21 20:30:29 -03:00
caobox-cms.txt Standardize leading slases in web conent 2023-05-18 23:55:53 +12:00
cms-configuration-files.txt Update cms-configuration-files.txt 2024-02-02 10:19:29 +01:00
ColdFusion.fuzz.txt Standardize leading slases in web conent 2023-05-18 23:55:53 +12:00
Django.txt
dotnetnuke.txt Adding wordlist for DotNetNuke resources 2022-12-20 14:18:21 -06:00
drupal-themes.fuzz.txt
Drupal.txt
flyspray-1.0RC4.txt
joomla-plugins.fuzz.txt strip trailing whitespace 2020-05-27 14:26:51 +01:00
joomla-themes.fuzz.txt
kentico-cms-modules-themes.txt Standardize leading slases in web conent 2023-05-18 23:55:53 +12:00
liferay_dxp_default_portlets.txt Standardize leading slases in web conent 2023-05-18 23:55:53 +12:00
modx-revolution-plugins
php-nuke.fuzz.txt
piwik-3.0.4.txt
README.md fix(docs): Moved 'aem2.txt' into the CMS directory 2025-02-21 20:30:29 -03:00
SAP.fuzz.txt Standardize leading slases in web conent 2023-05-18 23:55:53 +12:00
Sharepoint.fuzz.txt Standardize leading slases in web conent 2023-05-18 23:55:53 +12:00
sharepoint.txt strip trailing whitespace 2020-05-27 14:26:51 +01:00
shopware.txt Standardize leading slases in web conent 2023-05-18 23:55:53 +12:00
sitecore Standardize leading slases in web conent 2023-05-18 23:55:53 +12:00
Sitefinity-fuzz.txt
sitemap-magento.txt Standardize leading slases in web conent 2023-05-18 23:55:53 +12:00
SiteMinder.fuzz.txt Standardize leading slases in web conent 2023-05-18 23:55:53 +12:00
symfony-315-demo.txt
symphony-267-xslt-cms.txt
Umbraco.fuzz.txt Standardize leading slases in web conent 2023-05-18 23:55:53 +12:00
Umbraco.txt Standardize leading slases in web conent 2023-05-18 23:55:53 +12:00
wordpress.fuzz.txt Update wordpress.fuzz.txt 2024-10-28 14:52:49 +01:00
wp-plugins.fuzz.txt add site-editor and mail-masta 2022-09-15 04:06:39 +02:00
wp-themes.fuzz.txt

CMS Wordlists

These wordlists are specific to Content Management Systems.

AdobeCQ-AEM_2017.txt

Use for: Discovering sensitive filepaths of Adobe Experience Manager Creation date: Oct 1, 2017 No updates have been made to this wordlist since its creation.

Oracle-EBS-wordlist.txt

Use for: Fuzzing for common filepaths of Oracle E-Business Suite (EBS) version 11.

EBS v11 exposes:

  • usernames
  • ports
  • OS information
  • protocol information
  • Unauthenticated file upload
  • Cookie contents
  • SHA-1 hashed passwords

As an Unauthenticated user it's also possible to:

  • Create forms
  • Get servlets status
  • Get certain configuration files

Reference: https://the-infosec.com/2017/03/29/do-you-know-what-your-erp-is-telling-us/

Date of last update: Oct 7, 2019