
Reproduction environment and exploit script for CVE-2020-1938 (Apache Tomcat Ghostcat) with automated attack execution and setup instructions.
Exploit script: https://laolisafe.com/thread-612-1-1.html
Environment:
apache-tomcat-8.5.32
java
powershell
exploit environment - python
Start Tomcat
sh ./startup.sh
Exploit

The tool is only for security research and internal self-inspection. Do not use the tool to launch illegal attacks. The user is responsible for any consequences.