Sploitus

Exploit for Code Injection in Vmware Spring Cloud Gateway

githubexploit Β· 2022-05-16

Exploit Code

README8 lines
## https://sploitus.com/exploit?id=1C1E0F3C-2472-5BC6-A967-B71B63F51BE9
# CVE-2022-22947  
Spring Cloud Gateway Actuator API SpEL expression injection and command execution (CVE-2022-22947) – Injection of Godzilla-like memory exploits  

Default key/pass in Base64 format:  
Note: The code does not clear the routing part; please handle it yourself. Testing environment: https://github.com/vulhub/vulhub/blob/master/spring/CVE-2022-22947/README.zh-cn.md  

Memory exploit class: https://github.com/whwlsfb/cve-2022-22947-godzilla-memshell