LogoClawIndex
CasesSkillsAbout
LogoClawIndex

exploit-file-download - File Download and LFI Vulnerability Tester

Detect and exploit arbitrary file download and LFI vulnerabilities using curl, ffuf, and wget

Tags

Updated: 2026-06-30

Capabilities

Typical Inputs

Typical Outputs

What this skill does

  • detect LFI vulnerabilities
  • test path traversal
  • read sensitive files
  • use PHP wrappers
  • bypass filters
  • test file download
  • analyze PHP source code
  • inject log poisoning
  • execute commands
  • test URL encoded payloads
  • download files
  • enumerate directories
  • test database configurations
  • test extension bypass
  • evade WAF
  • read log files

Inputs

  • target URL
  • file parameter name
  • LFI payload list
  • PHP code snippet
  • web server log path
  • authorization documentation

Outputs

  • vulnerability detection result
  • downloaded files
  • read file content
  • command execution output
  • test results file
  • database records

Requirements

  • curl installed
  • ffuf installed
  • wget installed
  • explicit written authorization
  • compliance with local laws

Source

  • Spec: SKILL.md

ClawIndex

OpenClaw Skills & Use Case Index

ClawIndex is an ecosystem-driven index of OpenClaw skills and real-world use cases.

Index

Skills·
Cases

Meta

About·
Disclaimer·
Email·
GitHub
© 2026 ClawIndex All Rights Reserved.
security testing
vulnerability scanner
web security
penetration testing
LFI
file inclusion
path traversal
detect LFI vulnerabilities
test path traversal
read sensitive files
use PHP wrappers
target URL
file parameter name
LFI payload list
vulnerability detection result
downloaded files
read file content