
PoC environment and exploit for the Apache Tomcat on Windows Remote Code Execution Vulnerability
This is a proof of concept environment and exploit for known CVEs, strictly for learning and educational purposes.
Do not use these scripts or techniques on systems you do not own or have explicit permission to test. Unauthorised access or exploitation of systems is illegal and unethical.
This is a proof of concept environment and exploit for CVE 2017-12615.
The vulnerability arises in Tomcat with the following factors:
readonly=falseHTTP PUT requests are allowedAs such attackers may send and thus upload a JSP file via PUT a request. Apache Tomcat will then execute the code and render the response, rendering it vulnerable to remote code execution (RCE)
docker compose build
docker compose up -d
pip install -r requirements.txt
python CVE-2017-12615.py [TARGETIP:PORT]
If the exploit was successful, you may check if your file was uploaded by going to the target address at http://target-host/test.jsp or using curl http://target-host:port/test.jsp
You may choose to upload your own file by specifying the file location as such:
python CVE-2017-12615.py [TARGETIP:PORT] -f [file_path]