
springFramework_CVE-2022-22965_RCE简单利用
spring core rce simple exploitation
A war file is available at
https://github.com/fengguangbin/spring-rce-war
For Docker environment, you can use
https://github.com/lunasec-io/Spring4Shell-POC
You can also use the online environment at
http://vulfocus.io/
or the vulhub vulnerable environment at
https://github.com/vulhub/vulhub/tree/master/spring/CVE-2022-22965
In the vulfocus environment, the Behinder webshell could be uploaded but could not connect. Added the Godzilla shell for testing.
Just specify the url and type
type (default: 1)
1 --> Test if the vulnerability exists
2 --> Inject Behinder webshell, password rebeyond
3 --> Inject Godzilla webshell, password pass
Optional parameters
filename --> File name (default inject)
directory --> Write path (default webapps/ROOT)