The Path Traversal / Local File Inclusion Detection Accuracy of Web Application Scanners

The current information is based on the results of the *2011/2012/2014/2016* benchmarks (excpet for entries marked as updated or new )

Last updated: 18/09/2016, Currently compares 23 scanners
Sorted in a descending order according to the scanner Path Traversal/LFI detection ratio and product name.
Hint: click the version link to get more information about each scanner evaluation, and the product name to get detailed information on the product.

Unified List   Commercial Scanners   Free / Open Source Scanners


Rank
#
LogoVulnerability ScannerVersionVendorDetection AccuracyChart
1
IBM AppScan9.0.0.999 / 8.8.0.0IBM Security Systems Division100.00% Detection Rate
0.00% False Positives
(816/816)
(0/8)
1
Netsparker4.1.1.0Netsparker Ltd100.00% Detection Rate
0.00% False Positives
(816/816)
(0/8)
1
Tinfoil SecurityXTinfoil Security100.00% Detection Rate
0.00% False Positives
(816/816)
(0/8)
2
Netsparker Cloud2015-06-16Netsparker Ltd94.36% Detection Rate
0.00% False Positives
(770/816)
(0/8)
3
Acunetix WVS10.5Acunetix94.12% Detection Rate
0.00% False Positives
(768/816)
(0/8)
4
N-StalkerXN-Stalker92.77% Detection Rate
12.50% False Positives
(757/816)
(1/8)
5
WebInspect10.1.177.0HP Application Security Center91.18% Detection Rate
0.00% False Positives
(744/816)
(0/8)
6
AppSpider6.0Rapid781.13% Detection Rate
12.50% False Positives
(662/816)
(1/8)
7
Burp Suite Professional1.7.03PortSwigger69.12% Detection Rate
12.50% False Positives
(564/816)
(1/8)
8
Ammonite1.2RyscCorp.63.97% Detection Rate
37.50% False Positives
(522/816)
(3/8)
9
Syhunt Dynamic5.0.0.7Syhunt52.94% Detection Rate
0.00% False Positives
(432/816)
(0/8)
10
JSky (Commercial Edition)3.5.1NoSec48.53% Detection Rate
12.50% False Positives
(396/816)
(1/8)
11
ParosPro1.9.12MileSCAN Technologies12.75% Detection Rate
37.50% False Positives
(104/816)
(3/8)

Copyright © 2010-2015 by Shay Chen. All rights reserved.
Click here to learn how this information may be published or reused.