
CVE-2017-10352 CVE-2017-10271 weblogic-XMLDecoder
This software is for learning and communication only, any illegal use is prohibited #Weblogic-XMLDecoder-GUI CVE-2017-10352 A Python GUI experimental tool. Its main function is to exploit the deserialization vulnerability caused by Weblogic XMLDecoder. Developed for learning the Python tkinter library and ttk extensions. Later it will be packaged as a Windows executable file, mainly targeting vulnerabilities CVE-2017-10271 and CVE-2017-10352. Why two vulnerabilities? Because Oracle's first patch was not well applied. The screenshot below is from Mac, and the effect is average.

P.S: Submitted on the third day of the Chinese New Year (a traditional festival). Originally planned to finish on New Year's Eve, but got a bit tired from preparing the New Year's Eve dinner, so it was delayed until the third day (evidence in the picture).
Special thanks to https://github.com/s3xy/CVE-2017-10271, modifications were made based on this.
GitHub porter
forked from https://github.com/s3xy/CVE-2017-10271