
geforkt von https://github.com/s3xy/CVE-2017-10271. Schwachstelle in der Oracle WebLogic Server Komponente von Oracle Fusion Middleware (Unterkomponente: WLS Security). Betroffene unterstützte Versionen sind 10.3.6.0.0, 12.1.3.0.0, 12.2.1.1.0 und 12.2.1.2.0. Leicht ausnutzbare Schwachstelle ermöglicht es einem nicht authentifizierten Angreifer mit Netzwerkzugriff über HTTP, den Oracle WebLogic Server zu kompromittieren. Modifiziert von hanc00l.
Weblogic wls-wsat Komponente Deserialisierungsschwachstelle (CVE-2017-10271) Exploit-Skript, basierend auf https://github.com/s3xy/CVE-2017-10271 modifiziert.
Verwendung und Parameter
usage: weblogic_wls_wsat_exp.py [-h] -t TARGET [-c CMD] [-o OUTPUT] [-s SHELL]
optional arguments:
-h, --help show this help message and exit
-t TARGET, --target TARGET
weblogic ip and port(eg -> 172.16.80.131:7001)
-c CMD, --cmd CMD command to execute,default is "id"
-o OUTPUT, --output OUTPUT
output file name,default is output.txt
-s SHELL, --shell SHELL
local jsp file name to upload,and set -o xxx.jsp