CVE-2019-0232 is an OS command-injection vulnerability in the Apache Tomcat CGI Servlet on Windows. In affected Tomcat releases, the interaction between CGI command-line argument handling and Windows Java Runtime Environment command-line parsing permits attacker-controlled CGI arguments to be interpreted as additional command input. This can result in remote code execution when the CGI Servlet and command-line argument support are enabled.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.
What an attacker gets, and what they’ve been doing with it.
If you can’t patch tonight, do this now.
Patch, then assume compromise.
11 valid exploits after Mallory filtered fakes, detection scripts, and README-only repos (1 hidden).
This repository is a small standalone Python proof-of-concept exploit for CVE-2019-0232, targeting Apache Tomcat’s CGIServlet on Windows when enableCmdLineArguments=true is enabled and a batch CGI script is exposed. The repository contains four files: a README with vulnerability description and usage examples, a single Python exploit script (cve-2019-0232.py), a minimal requirements.txt listing requests, and a .gitignore. The exploit is not part of a larger framework. The main script uses argparse to expose three modes: check, exec, and revshell. The check mode performs a simple HTTP GET to a CGI path (default /cgi/ism.bat) to verify that a candidate CGI endpoint exists and returns HTTP 200. The exec mode constructs an exploit URL by appending a query string beginning with ?& followed by a URL-encoded command, relying on Windows batch parsing semantics to treat & as a command separator and thereby achieve arbitrary command execution. The response body is printed if present, allowing basic command output retrieval. The revshell mode is more operational: it sends two requests. First, it executes a certutil command on the victim to download nc.exe from an attacker-controlled HTTP server. Second, it executes nc.exe with -e cmd.exe to create a reverse shell back to the attacker. The script includes operator guidance for starting a Python HTTP server and a netcat listener. TLS verification can be disabled with -k/--insecure. Overall, this is a real exploit rather than a detector. It provides practical remote code execution against a misconfigured Tomcat CGI deployment on Windows and includes a hardcoded but functional reverse-shell workflow.
This repository is a Dockerized lab for reproducing CVE-2019-0232, a Windows-only Apache Tomcat CGI Servlet remote code execution issue. It is not an automated exploit tool; instead it provisions a vulnerable environment and documents a working exploit request. The core exploit-enabling changes are in tomcat/apache-tomcat-9.0.17/webapps/ROOT/WEB-INF/web.xml, which enables org.apache.catalina.servlets.CGIServlet with enableCmdLineArguments=true and maps it to /cgi-bin/*, and in tomcat/apache-tomcat-9.0.17/conf/context.xml, which sets privileged="true". The reachable CGI script is tomcat/apache-tomcat-9.0.17/webapps/ROOT/WEB-INF/cgi-bin/test.bat. On Windows, attacker-controlled query-string arguments are passed to the batch file / cmd interpreter, enabling arbitrary command execution; the README demonstrates this with /cgi-bin/test.bat?&dir. Repository structure: top-level Dockerfile builds a Windows Server Core container, downloads OpenJDK 11, copies in a bundled Apache Tomcat 9.0.17 tree, and exposes port 8080. docker-compose.yml publishes 8080:8080. Most of the repository contents are the stock Tomcat 9.0.17 distribution and documentation, not exploit logic. The meaningful files for the vulnerability are README.md, Dockerfile, docker-compose.yml, conf/context.xml, webapps/ROOT/WEB-INF/web.xml, and webapps/ROOT/WEB-INF/cgi-bin/test.bat. Capabilities: provision vulnerable Tomcat on Windows, expose HTTP service, and allow remote unauthenticated command execution through CGI argument injection when the target is queried over HTTP. No reverse shell, persistence, or post-exploitation automation is included, so this is best classified as a proof-of-concept lab rather than a weaponized exploit.
This repository is a compact standalone Python exploit for CVE-2019-0232, an Apache Tomcat CGI Servlet remote code execution issue affecting Windows deployments when enableCmdLineArguments=true. The repository contains 5 files total: one main Python script (cve_2019_0232.py), a README with usage and vulnerability details, requirements.txt listing requests, plus license and gitignore files. The exploit is not part of a larger framework. The main entry point is cve_2019_0232.py, a Python 3 CLI tool using requests, argparse, threading, socket, urllib.parse, and ThreadPoolExecutor. Based on the README and visible code structure, the script implements a multi-phase workflow: Tomcat enumeration, CGI path discovery/fuzzing, RCE verification, single-command execution, interactive HTTP shell, and reverse shell delivery. Core exploit behavior: it abuses Tomcat's handling of CGI query strings on Windows by injecting %26 (URL-encoded &) into the query string so that cmd.exe /c interprets a second attacker-controlled command after the CGI batch file. The script builds injection URLs that wrap the operator command in a grouped Windows command sequence, prepends a PATH modification to include Windows system directories, inserts echo. to satisfy CGI output handling, and appends 2>&1 so stderr is merged into stdout. This improves reliability for commands like whoami, ipconfig, netstat, and powershell.exe. Capabilities observed from the repository content: - Enumerates Tomcat and attempts version detection from HTTP responses. - Checks whether the target appears to be Tomcat and identifies possible CGI exposure. - Fuzzes likely CGI directories and common .bat/.cmd script names using multiple threads and optional custom wordlists. - Verifies code execution with a marker-based test. - Executes a single arbitrary command and prints the HTTP response body. - Provides an interactive HTTP shell where each command is sent as a fresh exploit request. - Can trigger a reverse shell back to the attacker using either a Base64-encoded PowerShell payload or a certutil stager fallback. - Supports proxying through an HTTP proxy such as Burp and optional TLS verification disabling. Fingerprintable target paths are primarily Tomcat CGI locations and candidate batch/cmd script names. The built-in base paths are /cgi-bin/, /cgi/, /scripts/, and /servlet/cgi/. The built-in script-name wordlist includes cmd.bat/cmd.cmd and other likely names such as hello, test, run, exec, shell, ping, debug, admin, index, and default with .bat/.cmd extensions. These are used to discover reachable CGI endpoints suitable for exploitation. Overall, this is a real exploit PoC with operational features beyond simple detection. It is best classified as OPERATIONAL rather than WEAPONIZED because it includes usable payload delivery and shell functionality, but it is still a standalone script rather than a reusable exploitation framework module.
This repository is a small standalone Python proof-of-concept exploit for unauthenticated remote code execution through a vulnerable CGI batch endpoint. The repository contains only two files: a README with operator instructions and exploit.py, the sole code file and clear entry point. The exploit logic is straightforward and two-staged. First, it takes a user-supplied target CGI URL and appends a query string containing command-chaining syntax to invoke the Windows binary C:\Windows\System32\certutil on the remote host. That command downloads nc.exe from an attacker-controlled HTTP server to the target. Second, after a short delay, it sends another HTTP GET request to the same CGI endpoint to execute nc.exe with attacker-supplied callback IP and port, using '-e cmd.exe' to provide a Windows command shell over the reverse connection. The exploit is operational rather than a mere detection script because it delivers a working payload chain and attempts exploitation directly. It is not tied to a named framework such as Metasploit or Nuclei. No specific CVE is referenced in the code or README; the targeting is generic to Windows-based CGI .bat endpoints that unsafely execute query-string input. Fingerprintable artifacts include the target CGI .bat path, the attacker-hosted HTTP URL serving nc.exe, the use of certutil from the Windows System32 path, the dropped nc.exe filename, and the reverse-shell callback IP/port. Overall, the repository's purpose is to achieve unauthenticated RCE and interactive shell access on a vulnerable Windows CGI target.
This repository contains a Python exploit script (CVE-2019-0232.py) and a README.md for CVE-2019-0232, a remote code execution vulnerability in Apache Tomcat on Windows with CGI enabled. The script provides two main exploitation modes: command execution and reverse shell. In command execution mode, it sends a crafted HTTP GET request to the vulnerable CGI endpoint, causing the server to execute arbitrary commands via cmd.exe. In reverse shell mode, it hosts nc.exe on an HTTP server, uploads it to the target using certutil, and then triggers a reverse shell back to the attacker's machine. The script validates required arguments, constructs payload URLs, and automates the exploitation process. The README provides usage instructions, options, and references. No hardcoded IPs or domains are present; endpoints are constructed from user-supplied arguments. The exploit is operational and suitable for real-world exploitation of vulnerable Tomcat servers.
This repository contains a Python exploit script (tomcat_cgi_exploit.py) targeting Apache Tomcat servers with CGI enabled, specifically on Windows platforms. The exploit automates the process of delivering a reverse shell to the attacker by first instructing the target to download netcat (nc.exe) using certutil, and then executing netcat to connect back to the attacker's listener, providing a shell (cmd.exe). The script is configurable via command-line arguments for target and attacker IPs, ports, and the CGI script name. The repository includes a README.md with usage instructions and requirements. The main attack vector is network-based, exploiting the Tomcat CGI interface via crafted HTTP requests. No hardcoded endpoints are present; all are dynamically constructed from user input. The exploit is operational, requiring the attacker to host nc.exe and set up a listener to receive the shell.
This repository contains a single Metasploit module (modules/exploits/windows/http/tomcat_cgi_cmdlineargs.rb) that exploits CVE-2019-0232, a remote code execution vulnerability in Apache Tomcat's CGIServlet on Windows. The exploit targets systems where the 'enableCmdLineArguments' setting is enabled, allowing attackers to execute arbitrary system commands via specially crafted HTTP GET requests to a CGI script. The module uses Metasploit's command stager to deliver a VBS payload, executed via cscript.exe, enabling remote code execution. The module is weaponized, supporting customizable payloads and session handling. The only fingerprintable endpoints are the HTTP path to the CGI script (default '/') and the use of cscript.exe on the target. The repository is structured as a typical Metasploit exploit module, with all logic contained in a single Ruby file.
This repository contains a Python exploit script (CVE-2019-0232.py) and a README.md for Apache Tomcat CVE-2019-0232, a remote code execution vulnerability affecting Tomcat on Windows (versions 6.x to 9.x). The exploit works by sending two crafted HTTP requests to the vulnerable server's /cgi/ism.bat endpoint. The first request uses certutil to download a Netcat binary (nc.exe) from an attacker-controlled server to the target. The second request executes nc.exe to spawn a reverse shell, connecting back to the attacker's Netcat listener. The script is interactive, prompting the user for all necessary parameters (target host/port, server IP/port for nc.exe, and Netcat listener IP/port). The README provides detailed usage instructions, requirements, and a disclaimer. The exploit is operational and provides a working reverse shell if the target is vulnerable and properly configured.
This repository provides a proof-of-concept exploit for command injection on Apache Tomcat 8.5.39 running on Windows with JDK 8u121. The exploit leverages Tomcat's CGI Servlet functionality by deploying a custom batch file (hello.bat) as a CGI script. The README.md details the required Tomcat and JDK versions, and provides step-by-step instructions for configuring web.xml to enable the CGI Servlet and mapping it to /cgi-bin/*. The hello.bat script is designed to take a command from the HTTP GET parameter, assign it to a variable, and execute it, thus allowing arbitrary command execution on the server. The exploit is triggered by sending crafted HTTP requests to the /cgi-bin/hello.bat endpoint, passing Windows commands as parameters. The repository structure is minimal, containing the exploit batch file, the necessary web.xml configuration, and documentation. No detection scripts or fake elements are present; this is a working proof-of-concept for remote command execution via misconfigured CGI on Tomcat.
This repository provides a proof-of-concept exploit for CVE-2019-0232, a remote code execution vulnerability in Apache Tomcat's CGI Servlet on Windows when 'enableCmdLineArguments' is enabled. The repository contains two files: a Python script (CVE-2019-0232.py) and a detailed README.md. The Python script automates exploitation by sending crafted HTTP requests to a vulnerable Tomcat server, first using certutil to download netcat (nc.exe) from an attacker-controlled server, then executing netcat to establish a reverse shell back to the attacker's listener. The README.md provides comprehensive setup and exploitation instructions, including required Tomcat configuration changes and mitigation advice. The exploit targets Tomcat versions 7.0.0 to 7.0.93, 8.5.0 to 8.5.39, and 9.0.0.M1 to 9.0.17 on Windows. The main attack vector is network-based, leveraging HTTP requests to the CGI endpoint. The exploit is a functional proof-of-concept and not weaponized, as it requires manual configuration and setup.
This repository contains a Python proof-of-concept exploit for CVE-2019-0232, a remote code execution vulnerability in Apache Tomcat on Windows when CGI is enabled. The exploit consists of a single Python script (CVE-2019-0232.py) that takes a target URL and a command as arguments. It constructs a malicious HTTP GET request to a CGI .bat file (e.g., /cgi-bin/hello.bat) on the Tomcat server, appending a Windows command to be executed. The script then sends the request and prints the response, which may contain the output of the executed command. The README provides setup instructions for a vulnerable Tomcat environment and references for further information. The exploit targets Tomcat 8.5.39 on Windows with CGI enabled and demonstrates the ability to execute arbitrary system commands remotely via a network attack vector.
Products and vendors Mallory has correlated with this vulnerability. Open in Mallory to drill down to specific CPE configurations and version ranges.
Vendor-confirmed product mapping. Mallory continuously reconciles this list against your asset inventory.
4 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Apache Tomcat on Windows remote code execution condition related to CGI handling (requires accessible /cgi-bin and batch files), discussed as a possible but ultimately non-applicable exploit path in this scenario.
Unknown.
A remote code execution vulnerability in Apache Tomcat's CGI Servlet on Windows when enableCmdLineArguments is enabled.
Specific vulnerability listed as an example in EPSS probability rankings; the content does not describe the flaw itself.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.