Skip to content
KitploitKITPLOIT
ToolsBlog
Submit
ToolsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories
spring-core-rce — springFramework_CVE-2022-22965_RCE简单利用 | Kitploit
Tools/GitHubGitHub/liangyueliangyue/spring-core-rce
Payload GenerationVulnerability AnalysisExploitationShellcodeWeb Application ExploitationPenetration Testing
GitHubliangyueliangyue/spring-core-rce

spring-core-rce

springFramework_CVE-2022-22965_RCE简单利用

View Repository
2664 years agoReviewed by Kitploit

Most Popular

View all →

Discover the most used tools by our community.

Explore all tools

Browse our collection of tools

View all tools →
Share

spring-core-rce

spring core rce simple exploitation

A war file is available at
https://github.com/fengguangbin/spring-rce-war
For Docker environment, you can use
https://github.com/lunasec-io/Spring4Shell-POC

You can also use the online environment at
http://vulfocus.io/
or the vulhub vulnerable environment at
https://github.com/vulhub/vulhub/tree/master/spring/CVE-2022-22965

In the vulfocus environment, the Behinder webshell could be uploaded but could not connect. Added the Godzilla shell for testing.

Just specify the url and type
type (default: 1)
1 --> Test if the vulnerability exists
2 --> Inject Behinder webshell, password rebeyond
3 --> Inject Godzilla webshell, password pass
Optional parameters
filename --> File name (default inject)
directory --> Write path (default webapps/ROOT)

Download Tool