VMware Workspace ONE Access 和 Identity Manager 通过 SSTI 的远程代码执行漏洞。
CVE-2022-22954 - 概念验证 SSTI
用法:
CVE-2022-22954.py [-h] -m SET_MODE [-i IP] [-c CMD]
optional arguments:
-h, --help show this help message and exit
-m SET_MODE, --mode SET_MODE
Available modes: shodan | file | manual
-i IP, --ip IP Host IP
-c CMD, --cmd CMD Command string
这只是一个概念验证。请在使用时自担风险,不要在生产环境或真实环境中使用。不要问我为什么代码写成这样,或者它好不好,我不在乎。我不是一个酷炫的程序员,我的代码很丑。