Overview
Imported from the upstream repository s4n7h0/NSE. “http-lfi.nse can discover LFI exploit in a web server using the resource value provided. this supports LFI discovery in both windows and linux servers, at the same time, it also supports LFI in private pages using a given cookie value. It hopes 20 times backword in the directory and looks for either boot.ini or /etc/passwd file in the webserver and extract the vulnerable path.”