Skip to content
KitploitKITPLOIT
ToolsBlog
Submit
ToolsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories
weblogic-XMLDecoder — CVE-2017-10352 CVE-2017-10271 weblogic-XMLDecoder | Kitploit
Tools/GitHubGitHub/bigsizeme/weblogic-xmldecoder
Payload GenerationVulnerability AnalysisExploitationWeb Application ExploitationPenetration TestingRemote Access Tool
GitHubbigsizeme/weblogic-xmldecoder

weblogic-XMLDecoder

CVE-2017-10352 CVE-2017-10271 weblogic-XMLDecoder

View Repository
97138 years agoNot yet reviewed

Most Popular

View all →

Discover the most used tools by our community.

Explore all tools

Browse our collection of tools

View all tools →
Share

This software is for learning and communication only, any illegal use is prohibited #Weblogic-XMLDecoder-GUI CVE-2017-10352 A Python GUI experimental tool. Its main function is to exploit the deserialization vulnerability caused by Weblogic XMLDecoder. Developed for learning the Python tkinter library and ttk extensions. Later it will be packaged as a Windows executable file, mainly targeting vulnerabilities CVE-2017-10271 and CVE-2017-10352. Why two vulnerabilities? Because Oracle's first patch was not well applied. The screenshot below is from Mac, and the effect is average.

image

P.S: Submitted on the third day of the Chinese New Year (a traditional festival). Originally planned to finish on New Year's Eve, but got a bit tired from preparing the New Year's Eve dinner, so it was delayed until the third day (evidence in the picture).

image

image

Special thanks to https://github.com/s3xy/CVE-2017-10271, modifications were made based on this.

GitHub porter

forked from https://github.com/s3xy/CVE-2017-10271

Download Tool