
提供批量扫描URL以及执行命令功能。Workspace ONE Access 模板注入漏洞,可执行任意代码
Workspace ONE Access provides a unified application portal through which all enterprise applications can be accessed securely, and can be used for single sign-on. In CVE-2022-22954, an attacker can craft a malicious request to cause template injection, execute arbitrary code, and take control of the server.
https://www.tenable.com/blog/vmware-patches-multiple-vulnerabilities-in-workspace-one-vmsa-2022-0011
python3 CVE-2022-22954.py -m scan -f 123.txt

python3 CVE-2022-22954.py -u https://xxx.xxx.com:8443 -c id
