Skip to main content

Search webroots for known vulnerable versions of web applications

Project description

freewvs

A local web vulnerability scanner.

freewvs is a tool to search webroots for known vulnerable versions of web applications.

install

You can install freewvs via pip:

pip install freewvs

Alternatively, you can run freewvs directly from the git source.

If you install via pip, you need to update the freewvs database first:

update-freewvsdb

usage

Just run freewvs with a path, e.g.:

freewvs /var/www

The output will be something like this:

Joomla 3.9.11 (3.9.14) CVE-2019-19846 /var/www/example.org
nextcloud 14.0.1 (14.0.5) CVE-2019-5449 /var/www/cloud.example.org
MediaWiki 1.31.1 (1.31.6) CVE-2019-19709 /var/www/wiki.example.org

faq

What does freewvs do?

It scans your webroot for known vulnerable versions of popular web applications.

What does the output tell me?

The output looks like this:

Joomla-3 3.9.11 (3.9.13) CVE-2019-18674 /home/joe/websites/joessite/

This says that in /home/joe/websites/joessite/, there's a Joomla installation of version 3.9.11. This version is vulnerable to CVE-2019-18674, and you should update it to version 3.9.13.

CVE-2019-XXXX seems to be very minor, at least it doesn't affect me. Am I safe?

No, as freewvs only checks for the latest vulnerabilities. There may be other vulnerabilities in your version not listed by freewvs. The only way to be sure is to check the upstream changelog.

There is no version inside the brackets. What does that mean?

It means your web application has not released a security update. Often, this means the software is no longer developed.

contributions

See CONTRIBUTIONS.md.

misc

freewvs was developed by schokokeks.org hosting.

It's licensed under the 0BSD license.

https://freewvs.schokokeks.org

Project details


Download files

Download the file for your platform. If you're not sure which to choose, learn more about installing packages.

Source Distribution

freewvs-0.1.5.tar.gz (19.9 kB view details)

Uploaded Source

Built Distribution

If you're not sure about the file name format, learn more about wheel file names.

freewvs-0.1.5-py3-none-any.whl (5.7 kB view details)

Uploaded Python 3

File details

Details for the file freewvs-0.1.5.tar.gz.

File metadata

  • Download URL: freewvs-0.1.5.tar.gz
  • Upload date:
  • Size: 19.9 kB
  • Tags: Source
  • Uploaded using Trusted Publishing? No
  • Uploaded via: twine/6.2.0 CPython/3.14.2

File hashes

Hashes for freewvs-0.1.5.tar.gz
Algorithm Hash digest
SHA256 1faf36f982e51b5d83e8a8e80d12cd8425685db81f86173312192bf41a80c779
MD5 f223c0e7592a1cd2a2705f0c7b358742
BLAKE2b-256 f588192ecd23a1de3e61739d327a20f05f8a7f1270a77501020c7db8c893d0b9

See more details on using hashes here.

File details

Details for the file freewvs-0.1.5-py3-none-any.whl.

File metadata

  • Download URL: freewvs-0.1.5-py3-none-any.whl
  • Upload date:
  • Size: 5.7 kB
  • Tags: Python 3
  • Uploaded using Trusted Publishing? No
  • Uploaded via: twine/6.2.0 CPython/3.14.2

File hashes

Hashes for freewvs-0.1.5-py3-none-any.whl
Algorithm Hash digest
SHA256 ac7c8058e51a59904b129580f894fa37e230d4c9583d859b63fc566443701225
MD5 5ff430c7d3468439bd7136412417a78c
BLAKE2b-256 414d7d4557a0d36858c92c76d343135f2ed35d0f0bea2a2a70df541c9ccdbe9a

See more details on using hashes here.

Supported by

AWS Cloud computing and Security Sponsor Datadog Monitoring Depot Continuous Integration Fastly CDN Google Download Analytics Pingdom Monitoring Sentry Error logging StatusPage Status page