Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1000 CNY

100.0%

CVE-2017-12615 PoC — Apache Tomcat 安全漏洞

Source
Associated Vulnerability
Title:Apache Tomcat 安全漏洞 (CVE-2017-12615)
Description:When running Apache Tomcat 7.0.0 to 7.0.79 on Windows with HTTP PUTs enabled (e.g. via setting the readonly initialisation parameter of the Default to false) it was possible to upload a JSP file to the server via a specially crafted request. This JSP could then be requested and any code it contained would be executed by the server.
Description
CVE-2017-12615 任意文件写入exp,写入webshell
Readme
# CVE-2017-12615-EXP

```
> .\CVE-2017-12615.exe 

 @@@@@@@ @@@  @@@ @@@@@@@@           @@@@@@   @@@@@@   @@@ @@@@@@@@           @@@  @@@@@@    @@@@@   @@@ @@@@@@@
!@@      @@!  @@@ @@!               @@   @@@ @@!  @@@ @@@@      @@!          @@@@ @@   @@@ @@!@     @@@@ !@@
!@!      @!@  !@! @!!!:!   @!@!@!@!   .!!@!  @!@  !@!  !@!     @!!  @!@!@!@!  !@!   .!!@!  @!@!@!@   !@! !!@@!!
:!!       !: .:!  !!:                !!:     !!:  !!!  !!!  .!!:              !!!  !!:     !!:  !!!  !!!     !:!
 :: :: :    ::    : :: ::           :.:: :::  : : ::   ::  : :                ::  :.:: :::  : : ::   ::  :: : :
                                                                                                             --w0x68y
Usage: CVE-2017-12615 <domain>
Shell usage: xxx.jsp?cmd=id&pwd=0909
```

以时间戳命名写入 webshell

![exp](exp测试.jpg)

![webshell](webshell.jpg)
File Snapshot

[4.0K] /data/pocs/ba853c4c7ddd5f681ffe57c8e237e688233a885e ├── [3.2K] CVE-2017-12615.go ├── [ 19K] exp测试.jpg ├── [ 885] README.md └── [ 25K] webshell.jpg 0 directories, 4 files
Shenlong Bot has cached this for you
Remarks
    1. It is advised to access via the original source first.
    2. Local POC snapshots are reserved for subscribers — if the original source is unavailable, the local mirror is part of the paid plan.
    3. Mirroring, verifying, and maintaining this POC archive takes ongoing effort, so local snapshots are a paid feature. Your subscription keeps the archive online — thank you for the support. View subscription plans →