๐Ÿš€ Acunetix is now Invicti Web + API. Read the announcement.
Get a demo Invicti Website Security Scanner Get a demo
  • Product
  • Why Invicti Web + API?
    • Solutions
      • INDUSTRIES
        • IT & Telecom
        • Government
        • Financial Services
        • Education
        • Healthcare
      • ROLES
        • CTO & CISO
        • Engineering Manager
        • Security Engineer
        • DevSecOps
    • Case Studies
    • Customers
    • Testimonials
  • Pricing
  • About Us
    • Our story
    • In the news
    • Careers
    • Contact
  • Resources
    • Blog
    • Webinars
    • White papers
    • Buyerโ€™s guide
    • Partners
    • Documentation
  • Get a demo

MANAGE YOUR WEB SECURITY WITH

RFI Vulnerability Scanner

Get a demo
Gartner Peer Insights Reviews

RFI Vulnerability Scanner – Enter Invicti!

Remote file inclusion (RFI) vulnerabilities are critical security issues within web applications since successful exploitation of such a vulnerability may lead to remote code execution (RCE). An RFI vulnerability allows an attacker to remotely include a file hosted on a malicious web server. Once successfully carrying out their RFI attack, the attacker would typically try to obtain a reverse shell which provides them with a command line session where arbitrary commands can be executed. RFI vulnerabilities are usually not difficult to fix, but finding them in large codebases could be challenging without the right tools. Invicti is a web application vulnerability scanner which, in addition to RFI, can test for LFI vulnerabilities and other file inclusion bugs, as well as Cross-site Scripting (XSS), SQL Injection (SQLi), and thousands of other vulnerabilities and misconfigurations.
Invicti web vulnerability scanner

Beyond Low-Hanging Fruit

The Invicti RFI scanner tests for both local file inclusion (LFI) and remote file inclusion (RFI). While many file inclusion vulnerability scanners can find low-hanging file inclusion, Invicti goes well beyond the basics thanks to its advanced crawler and JavaScript engine called DeepScan. Thanks to DeepScan, Invicti also has full support for modern single page applications (SPAs) and can understand and fully test applications that rely on JavaScript frameworks.
Invicti web vulnerability scanner

Runtime Source Code Analysis

In addition to being a fully automated black box scanner (no knowledge of back end code), Invicti also provides AcuSensor as part of its standard offering. AcuSensor is a an optional sensor for Java, ASP.NET, and PHP applications that can easily be deployed on the application backend to analyse source code while it is in execution by the scanner, giving even more accurate results and even fewer false positives.

Frequently asked questions

What is the best way to discover RFI vulnerabilities?

The best way to discover and then eliminate RFI vulnerabilities (remote file inclusion) is by using a vulnerability scanner. Web application firewalls (WAF) do not help you discover or prevent vulnerabilities, just make it difficult (but not impossible) for attackers to exploit them. With a vulnerability scanner, you can quickly identify and then eliminate all your vulnerabilities.

Learn more about the Invicti vulnerability scanner.

How dangerous are RFI vulnerabilities?

RFI vulnerabilities are very dangerous. If an attacker can include a remote file, they can potentially establish complete control over the web server. If the web server has other vulnerabilities, the attacker may propagate the attack to your other systems. RFI is also commonly used in conjunction with many other techniques, for example, phishing.

Read how attackers are using RFI in dangerous phishing campaigns.

How to eliminate and prevent RFI vulnerabilities?

Once you use Invicti to detect an RFI vulnerability, you can eliminate it by modifying the application code so that you do not include any files based on user input. If this is not possible, you must maintain a whitelist of files that can be included.

Read more about RFI vulnerabilities and how to avoid them.

What other vulnerabilities can Invicti detect?

Invicti can detect web vulnerabilities (for example, SQLi, XSS, CSRF, SSRF, LFI, RCE, and many more), but it is more than just a simple scanner. Invicti also comes with a full set of vulnerability assessment and vulnerability management features, and it integrates with many issue tracking tools, CI/CD, and other software.

Request a demo of Invicti to see how it can help you.

Recommended reading

Learn more about prominent vulnerabilities, keep up with recent product updates, and catch the latest news from Acunetix.

Knowledge Sharing

Knowledge Sharing

What is SQL Injection

What is Cross-site Scripting

What Are XML External Entity Attacks

What is Insecure Deserialization

Popular Posts

Popular Posts

SQL Injection Example

Preventing SQL Injection in PHP

TLS/SSL Cipher Hardening

Defending Against CSRF Attacks

In The News

In The News

2020 Web Application Vulnerability Report

Complimentary licenses โ€“ COVID-19

Interview with Acunetix President & COO

Innovations in Acunetix v13

Client: Xerox

โ€œWe use Acunetix as part of our Security in the SDLC and to test code in DEV and SIT before being promoted to Production.โ€

Kurt Zanzi, Xerox CA-MMIS Information Securtiy Office, Xerox
Read more case studies >

Take action and discover your vulnerabilities

Get a demo
Client: AWS
Client: Cognizant
Client: Garmin
Client: Airforce
Client: NASA
Client: American Express
Product Information
  • AcuSensor Technology
  • AcuMonitor Technology
  • Invicti Web + API Integrations
  • Vulnerability Scanner
  • Support Plans
Use Cases
  • Penetration Testing Software
  • Website Security Scanner
  • External Vulnerability Scanner
  • Web Application Security
  • Vulnerability Management Software
Website Security
  • Cross-site Scripting
  • SQL Injection
  • Reflected XSS
  • CSRF Attacks
  • Directory Traversal
Learn More
  • White Papers
  • TLS Security
  • WordPress Security
  • Web Service Security
  • Prevent SQL Injection
Company
  • About Us
  • Customers
  • Become a Partner
  • Careers
  • Contact
Documentation
  • Case Studies
  • Documentation
  • Videos
  • Vulnerability Index
  • Webinars
  • Login
  • Invicti Subscription Services Agreement
  • Privacy Policy
  • Terms of Use
  • Sitemap
  • Follow us on X
  • Follow us on LinkedIn

© Invicti Web + API 2026