
VMware vCenter Server任意文件上传漏洞 / Code By:Jun_sheng
Orange Network Security Lab https://0range.team/
This tool is only for authorized security testing. Unauthorized illegal attacks on sites are prohibited.
Read online 《Cybersecurity Law of the People's Republic of China》
python cve-2021-22005.py -h for help

Please submit bugs via Issues. I will check them when I have time.
All steps fail when using a proxy during exploitation.
v0.2 Update
Updated the initial default webshell to a JSP webshell that can be connected with Behinder (冰蝎) by the tool, and added the ability to upload custom webshells. Thanks to @Tas9er for providing the webshell. Additionally, the built-in bash_shell-like functionality has been removed.