
CVE-2022-22954 脆弱性テスト
VMware Workspace ONE Access および Identity Manager は、サーバーサイドテンプレートインジェクションにより、リモートコード実行の脆弱性を含んでいます。ネットワークアクセスを持つ悪意のある攻撃者は、リモートコード実行を引き起こす可能性のあるサーバーサイドテンプレートインジェクションをトリガーできます。
サーバーサイドテンプレートインジェクション リモートコード実行の脆弱性 (CVE-2022-22954) https://www.vmware.com/security/advisories/VMSA-2022-0011.html
必ず法的範囲内で使用してください。 不正使用については一切責任を負いません。
テストおよび学習目的です。
実行方法 python3 vmware.py http://.....
#-----------EN------------
VMware Workspace ONE Access and Identity Manager contain a remote code execution vulnerability due to server-side template injection. A malicious actor with network access can trigger a server-side template injection that may result in remote code execution.
Server-side Template Injection Remote Code Execution Vulnerability (CVE-2022-22954) https://www.vmware.com/security/advisories/VMSA-2022-0011.html
Please used within limitations. I Take No Responsibility for Illegal Use.
For Testing and Guidance Purposes.
Operating python3 vmware.py http://.....