Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1000 CNY

100.0%

CVE-2022-22947 PoC — VMware Spring Cloud Gateway 代码注入漏洞

Source
Associated Vulnerability
Title:VMware Spring Cloud Gateway 代码注入漏洞 (CVE-2022-22947)
Description:In spring cloud gateway versions prior to 3.1.1+ and 3.0.7+ , applications are vulnerable to a code injection attack when the Gateway Actuator endpoint is enabled, exposed and unsecured. A remote attacker could make a maliciously crafted request that could allow arbitrary remote execution on the remote host.
Description
CVE-2022-22947批量检测脚本,回显命令没进行正则,大佬们先用着,后续再更
Readme
# CVE-2022-22947-POC
CVE-2022-22947批量检测脚本,回显命令没进行正则,大佬们先用着,后续再更

将脚本路径下放上url.txt

直接执行python 脚本.py 

演示:
![image](https://user-images.githubusercontent.com/75511051/156756426-b0b59201-cb5c-4f1e-80d1-ee7b3342c70a.png)



检测完成之后会生成一个成功的txt

该脚本会将代码进行注入,刷新路由,回显命令,删除注入命令,大佬们勿喷,有什么bug明天解决
File Snapshot

[4.0K] /data/pocs/50217d65182fc7a2875196137ced4cb6ec0d576b ├── [4.4K] CVE-2022-22947_POC.py ├── [ 487] README.md └── [ 22] url.txt 0 directories, 3 files
Shenlong Bot has cached this for you
Remarks
    1. It is advised to access via the original source first.
    2. Local POC snapshots are reserved for subscribers — if the original source is unavailable, the local mirror is part of the paid plan.
    3. Mirroring, verifying, and maintaining this POC archive takes ongoing effort, so local snapshots are a paid feature. Your subscription keeps the archive online — thank you for the support. View subscription plans →