
tomcat CVE-2024-50379/CVE-2024-56337 条件竞争文件上传exp
Manual exploitation is troublesome, so I whipped up an exp..
Usage:
shell.jsp is the shell file, ggsl.jsp is the name/path saved to the target server.
./CVE-2024-50379 -u http://192.168.2.245:8080 -f shell.jsp -p ggsl.jsp


This tool is only intended for legally authorized enterprise security construction activities. If you need to test the availability of this tool, please set up your own target environment.
When using this tool for scanning, you must ensure that the action complies with local laws and regulations and that you have obtained sufficient authorization. Do not scan unauthorized targets.
If you engage in any illegal activities while using this tool, you must bear the corresponding consequences. We will not assume any legal or joint liability.
Before installing and using this tool, you must carefully read and fully understand the terms. Terms that limit or disclaim liability, or otherwise involve your significant rights, may be highlighted in bold or underlined form. Unless you have fully read, completely understood, and accepted all the terms of this agreement, please do not install or use this tool. Your use of the tool or any other express or implied acceptance of this agreement indicates that you have read and agreed to be bound by this agreement.