Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1359 CNY

100%

CVE-2022-22947 PoC — VMware Spring Cloud Gateway 代码注入漏洞

Source
Associated Vulnerability
Title: VMware Spring Cloud Gateway 代码注入漏洞 (CVE-2022-22947)
Description:In spring cloud gateway versions prior to 3.1.1+ and 3.0.7+ , applications are vulnerable to a code injection attack when the Gateway Actuator endpoint is enabled, exposed and unsecured. A remote attacker could make a maliciously crafted request that could allow arbitrary remote execution on the remote host.
Description
CVE-2022-22947批量检测脚本,回显命令没进行正则,大佬们先用着,后续再更
Readme
# CVE-2022-22947-POC
CVE-2022-22947批量检测脚本,回显命令没进行正则,大佬们先用着,后续再更

将脚本路径下放上url.txt

直接执行python 脚本.py 

演示:
![image](https://user-images.githubusercontent.com/75511051/156756426-b0b59201-cb5c-4f1e-80d1-ee7b3342c70a.png)



检测完成之后会生成一个成功的txt

该脚本会将代码进行注入,刷新路由,回显命令,删除注入命令,大佬们勿喷,有什么bug明天解决
File Snapshot

Log in to view the POC file snapshot cached by Shenlong Bot

Log in to view
Remarks
    1. It is advised to access via the original source first.
    2. Local POC snapshots are reserved for subscribers — if the original source is unavailable, the local mirror is part of the paid plan.
    3. Mirroring, verifying, and maintaining this POC archive takes ongoing effort, so local snapshots are a paid feature. Your subscription keeps the archive online — thank you for the support. View subscription plans →