Skip to content
KitploitKITPLOIT
工具博客
Log in
提交
工具博客
提交

黑客、渗透测试和网络安全工具,武装您的安全武器库!

Kitploit 是一个黑客、网络安全和渗透测试工具的目录。发现最新的项目更新,查找漏洞、分析系统、自动化测试并加强你的安全。

··订阅源·联系·隐私·© 2026 Kitploit

工具目录

分类

查看所有分类
Loading categories
Safer_PoC_CVE-2022-22965 — 针对 CVE-2022-22965 (Spring4Shell) 的基于 Python 的概念验证(PoC),它会向 Tomcat webapps 目录写入标记文件,并通过 HTTP 请求验证漏洞利用是否成功。 | Kitploit
工具/GitHubGitHub/colincowie/safer_poc_cve-2022-22965
Payload生成漏洞分析漏洞利用Web应用程序漏洞利用渗透测试
GitHubcolincowie/safer_poc_cve-2022-22965

Safer_PoC_CVE-2022-22965

针对 CVE-2022-22965 (Spring4Shell) 的基于 Python 的概念验证(PoC),它会向 Tomcat webapps 目录写入标记文件,并通过 HTTP 请求验证漏洞利用是否成功。

查看仓库

最受欢迎

查看全部 →

发现我们社区最常用的工具。

探索所有工具

浏览我们的工具集合

查看所有工具 →
分享
44714年前Kitploit 审核通过

Safer_PoC_CVE-2022-22965

一个针对 CVE-2022-22965 (Spring4Shell) 的更安全 PoC

功能

  • 在 tomcat 的 'webapps/ROOT' 目录中创建一个名为 CVE_2022-22965_exploited.txt 的文件
  • 可通过用户参数更改输出目录
  • 通过请求输出的 .txt 文件来执行漏洞验证,根据你的 tomcat 配置,这可能需要人工检查。
    • 增加了额外验证以检查返回文档的内容;某些 Web 服务器会返回 HTTP 状态为 200 的错误页面

使用方法

usage: Safer_PoC_CVE-2022-22965.py [-h] --url URL [--dir DIR]

CVE-2022-22965 Spring-Core remote code execution POC

optional arguments:
  -h, --help  show this help message and exit
  --url URL   target url
  --dir DIR   directory to write the result (default is "webapps")

示例:python3 Safer_PoC_CVE-2022-22965.py --url http://localhost:8080/handling-form-submission-complete/greeting --dir "webapps/handling-form-submission-complete"

输出文件

文件名:CVE_2022_22965_exploited.txt

文件内容:Warning, CVE_2022_22965 was sucessfully exploited on this device. reference: https://spring.io/blog/2022/03/31/spring-framework-rce-early-announcement

下载工具