目标达成 感谢每一位支持者 — 我们达成了 100% 目标!

目标: 1000 元 · 已筹: 1310

100%

CVE-2025-24813 PoC — Apache Tomcat 环境问题漏洞

来源
关联漏洞
标题:Apache Tomcat 环境问题漏洞 (CVE-2025-24813)
Description:Apache Tomcat是美国阿帕奇(Apache)基金会的一款轻量级Web应用服务器。用于实现对Servlet和JavaServer Page(JSP)的支持。 Apache Tomcat 11.0.0-M1至11.0.2版本、10.1.0-M1至10.1.34版本和9.0.0.M1至9.0.98版本存在环境问题漏洞。攻击者利用该漏洞可以远程执行代码或泄露敏感信息。
Description
Automated scanner + exploit for CVE-2025-24813
介绍
# CVE-2025-24813 Exploit Toolkit

This is an advanced and automated exploitation tool for **CVE-2025-24813**, targeting Apache Tomcat servers vulnerable to insecure session deserialization.

## 🔍 Features
- Multi-target scanning from file or single URL (`--targets` / `--url`)
- Automatic gadget chain testing (CommonsCollections1-7, BeanShell, Spring, etc.)
- OS detection and post-exploitation payloads (Linux/Windows)
- Session ID discovery from common endpoints
- Verbose logging to both console and file
- TLS (HTTPS) support with optional SSL verification disabling

## ⚙️ Usage

```bash
# Single target
python3 exploit_cve_2025_24813.py \
  --url http://target:8080 \
  --ysoserial ysoserial.jar \
  --no-ssl-verify

# Multiple targets from file
python3 exploit_cve_2025_24813.py \
  --targets targets.txt \
  --ysoserial ysoserial.jar \
  --no-ssl-verify
```

## 📥 Requirements

    Python 3.6+

    Java Runtime (for ysoserial)

    ysoserial Java binary

## ⚠️ Legal Disclaimer

This tool is provided for educational and authorized security testing purposes only. Any unauthorized use against systems you do not own or have explicit permission to test is strictly prohibited and may be illegal.
📚 Credits

This project was inspired by a public PoC published under the Apache License 2.0.
Original PoC author: absholi7ly
Enhanced and rewritten by mehrdad mirabi

文件快照

登录后查看神龙缓存的 POC 文件快照

登录查看
备注
    1. 建议优先通过来源进行访问。
    2. 本地 POC 快照面向订阅用户开放;当原始来源失效或无法访问时,本地镜像作为订阅权益的一部分提供。
    3. 持续抓取、验证、维护这份 POC 档案需要不少投入,因此本地快照已纳入付费订阅。您的订阅是让这份资料能继续走下去的关键,由衷感谢。 查看订阅方案 →