
CVE-2020-10199、CVE-2020-10204漏洞一键检测工具,图形化界面。CVE-2020-10199 and CVE-2020-10204 Vul Tool with GUI.
I wrote this small tool in Java in my spare time. It supports one-click detection of CVE-2020-10199 and CVE-2020-10204 vulnerabilities with a graphical interface. To ensure detection stability, random numbers are used in the payload. This tool is only for security professionals to use within the scope allowed by laws and regulations. Users are solely responsible for any consequences of misuse.


Cross-platform, JRE >= 1.6.
Sonatype Nexus is a Maven repository management system that provides powerful repository management, artifact search, and other functions. It can be used to build a private Maven repository server, proxying remote repositories while maintaining a local repository to save bandwidth and time. In Nexus Repository Manager OSS/Pro 3.21.1 and earlier versions, an authenticated attacker can cause remote code execution and obtain system privileges via JavaEL expression injection.
CVE-2020-10199 Official Description: https://support.sonatype.com/hc/en-us/articles/360044882533-CVE-2020-10199-Nexus-Repository-Manager-3-Remote-Code-Execution-2020-03-31
CVE-2020-10204 Official Description: https://support.sonatype.com/hc/en-us/articles/360044356194-CVE-2020-10204-Nexus-Repository-Manager-3-Remote-Code-Execution-2020-03-31
CVE-2020-10199: Nexus Repository Manager OSS/Pro <= 3.21.1, requires a low-privilege account.
CVE-2020-10204: Nexus Repository Manager OSS/Pro <= 3.21.1, requires an administrator account.
Upgrade Nexus Repository Manager OSS/Pro to the latest version. Download: https://help.sonatype.com/repomanager3/download?_ga=2.58824877.1855790103.1586413660-404515824.1586413660