
Burp Suite extension for detecting CVE-2022-42889 (Text4Shell) vulnerability via passive scanning of HTTP requests and responses.
This project is modified from log4j2burpscanner, with the active scanning feature removed. It will be added back later if needed.
CVE2022-42889
Target range link:
https://github.com/karthikuj/cve-2022-42889-text4shell-docker.git
You can also follow the main account's official account (only security) and reply text4shell to get the download link for the compiled target range.
Target range setup:
cd into the directory, execute
docker run -p 85:8080 text4shell
Visit http://<ip_address>/text4shell/attack?search=111
The vulnerability can be seen on the plugin page.
