Skip to content
KitploitKITPLOIT
ToolsBlog
Log in
Submit
ToolsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories
CVE-2022-46364-htb-ctf — Exploit CVE-2022-46364 in Apache CXF 3.2.14 for LFI and SSRF via MTOM/XOP injection. Automated multipart construction and Base64 extraction for HTB CTF environments. | Kitploit
Tools/GitHubGitHub/jwsly12/cve-2022-46364-htb-ctf
Vulnerability AnalysisExploitationWeb Application ExploitationCTFPenetration TestingLabs & Practice
GitHubjwsly12/cve-2022-46364-htb-ctf

CVE-2022-46364-htb-ctf

Exploit CVE-2022-46364 in Apache CXF 3.2.14 for LFI and SSRF via MTOM/XOP injection. Automated multipart construction and Base64 extraction for HTB CTF environments.

View Repository
186 months agoNot yet reviewed

Most Popular

View all →

Discover the most used tools by our community.

Explore all tools

Browse our collection of tools

View all tools →
Share

DevArea SOAP Exploitation Tool (CVE-2022-46364)

Description

This specialized exploit targets the DevArea environment on Hack The Box. It leverages a critical vulnerability in Apache CXF 3.2.14 (CVE-2022-46364) to perform Local File Inclusion (LFI) and Server-Side Request Forgery (SSRF).

The script abuses the MTOM/XOP (Message Transmission Optimization Mechanism) processing engine. By injecting an <xop:Include> element, we force the server's AttachmentDeserializer to fetch local system files or internal network resources and reflect them back in the SOAP response.

Features

  • Automated Multipart Construction: Handles the complex multipart/related structure required to trigger XOP processing.
  • LFI/SSRF via XOP: Supports file:/// for local files and http:// for internal service scanning.
  • Smart Extraction: Automatically identifies the <return> tag and decodes the Base64 content into readable text.

Prerequisites

  • Python 3.x
  • requests library (pip install requests)

Usage for LFI

python3 exploit.py -u http://machinename.htb:8080/employeeservice -r /etc/passwd

Usage for SSRF

python3 exploit.py -u http://machinename.htb:8080/employeeservice -r http://127.0.0.1:8080/api

Arguments

  • -u, --url: Target SOAP endpoint (usually http://devarea.htb:8080/employeeservice).
  • -r, --resource: Target Resource: Absolute local path for LFI (e.g., /etc/passwd) or internal service URL for SSRF (e.g., http://127.0.0.1:8888/api).

How It Works

  1. The Request: The script sends a POST request with a custom boundary and Content-Type: multipart/related.
  2. The Injection: It crafts a SOAP envelope where the content field contains an XOP pointer to the desired file.
  3. The Response: Since the server treats MTOM attachments as binary data, it encodes the file content in Base64 within the <return> tag.
  4. The Decode: The script captures this string, decodes it, and prints the cleartext content to your terminal.

Disclaimer

This tool is intended for use in Hack The Box CTF environments and authorized security testing only.


Download Tool