Sploitus

CVE-2017-12615

20 known exploits for CVE-2017-12615

When running Apache Tomcat 7.0.0 to 7.0.79 on Windows with HTTP PUTs enabled (e.g. via setting the readonly initialisation parameter of the Default to false) it was possible to upload a JSP file to the server via a specially crafted request. This JSP could then be requested and any code it contained would be executed by the server.

Affected products
Apache Tomcat, Centos, Red Hat, Suse
Apache Tomcat
≤ 7.0.79
Fix
Available
CVSS 3.1
8.1 HIGH
EPSS
99.6% (100th percentile)
Weakness
CWE-434
NVD status
Analyzed
Published
2017-09-19
CVE-2017-12615 at NVD
Authoritative description, scoring and affected products

20 known exploits for CVE-2017-12615

Proof-of-concept code and exploit modules indexed by Sploitus

CVE-Apache-Ecosystem
2026-08-13 chengbochuan3GITHUB
Exploit for Unrestricted Upload of File with Dangerous Type in Apache Tomcat
2026-07-03 K3ysTr0K3RGITHUB
Exploit for Unrestricted Upload of File with Dangerous Type in Apache Tomcat
2024-08-29 lizhianyuguangmingGITHUB
Exploit for Unrestricted Upload of File with Dangerous Type in Apache Tomcat
2024-08-29 lizhianyuguangmingGITHUB
Vulmap - Web Vulnerability Scanning And Verification Tools
2020-12-25 KitPloitKITPLOIT
Exploit for Deserialization of Untrusted Data in Redhat Jboss_Enterprise_Application_Platform
2020-12-08 Keepb1ueGITEE
Exploit for Unrestricted Upload of File with Dangerous Type in Apache Tomcat
2020-10-07 0xdawnGITEE
Exploit for Deserialization of Untrusted Data in Redhat Jboss_Enterprise_Application_Platform
2020-05-06 MstirGITEE
Exploit for Argument Injection in Phpmailer_Project Phpmailer
2019-12-05 Optic_FiberGITEE
Exploit for Unrestricted Upload of File with Dangerous Type in Apache Tomcat
2017-12-26 1337gGITHUB
Exploit for Unrestricted Upload of File with Dangerous Type in Apache Tomcat
2017-11-28 BeyondCyGITHUB
Exploit for Unrestricted Upload of File with Dangerous Type in Apache Tomcat
2017-10-06 zi0BlackGITHUB
Apache Tomcat JSP Upload Bypass / Remote Code Execution
2017-10-04 xxlegendPACKETSTORM
Apache Tomcat < 9.0.1 (Beta) / < 8.5.23 / < 8.0.47 / < 7.0.8 - JSP Upload Bypass Exploit
2017-10-04 xxlegendZDT
Exploit for Unrestricted Upload of File with Dangerous Type in Apache Tomcat
2017-09-23 breaktoprotectGITHUB
Tomcat information disclosure Vulnerability(CVE-2017-12616 )analysis
2017-09-21 RootSEEBUG
Apache Tomcat 9.0.1 (Beta) 8.5.23 8.0.47 7.0.8 - JSP Upload Bypass Remote Code Execution (1)
2017-09-20 xxlegendEXPLOITPACK
Apache Tomcat < 9.0.1 (Beta) / < 8.5.23 / < 8.0.47 / < 7.0.8 - JSP Upload Bypass / Remote Code Execution (1)
2017-09-20 xxlegendEXPLOITDB
Tomcat code execution vulnerability(CVE-2017-12615)
2017-09-20 RootSEEBUGPython
Immunity Canvas: TOMCAT_FILE_UPLOAD
2017-09-19 Immunity CanvasCANVAS