Spring4Shell RCE Exploit (CVE-2022-22965)
Versionv1.5
Difficulty Intermediate
Updated2025-03-10
CategoryExploits & 0days

Spring4Shell RCE Exploit (CVE-2022-22965)

$59.99

Spring4Shell — CVE-2022-22965 RCE

n

Exploit for the vulnerability of class loader manipulation in Spring Framework that allows escritura of files arbitrarios and remote code execution.

n
    n
  • Exploit Python — Script that modifies el AccessLogValve of Tomcat for escribir a webshell JSP in the directorio web.
  • n
  • Detection automatic — Verifica if the target es vulnerable probando the modifiestion of propiedades of the ClassLoader without efecto destructivo.
  • n
  • Webshell JSP — Shell minimalist that se writes via the exploit, with password protection.
  • n
  • Cleanup script — Restaura the configurestion original of the AccessLogValve post-exploitation.
  • n
n

Condiciones: Spring MVC o WebFlux, JDK 9+, desplegado as WAR in Tomcat. No works with JAR embedded.