
rwsploit
Automated exploitation scanner for Oracle Reports Server (rwservlet) — CVE-2012-3152 / CVE-2012-3153. Detects, fingerprints, reads files via LFI,…

Automated exploitation scanner for Oracle Reports Server (rwservlet) — CVE-2012-3152 / CVE-2012-3153. Detects, fingerprints, reads files via LFI,…

Python exploit for Oracle WebLogic CVE-2019-2725, enabling unauthenticated remote code execution via crafted HTTP requests to vulnerable servers.

Exploit for CVE-2025-61882, a critical pre-auth RCE in Oracle E-Business Suite. Combines SSRF, CRLF injection, HTTP smuggling, and XSLT injection for…

Payload generator for Java Binary Deserialization attack with Commons FileUpload (CVE-2013-2186)

Oracle Weblogic RCE - CVE-2022-2109

This script allows for remote code execution (RCE) on Oracle WebLogic Server

(CVE-2019-2725) Oracle WLS(Weblogic) RCE test sciript

Exploit for Oracle WebLogic CVE-2017-10271 (wls-wsat RCE bypass) with PoC scripts for remote command execution and obtaining a cmd shell on…

Unauthenticated remote code execution exploit for Oracle WebLogic Server (CVE-2019-2725) via deserialization in AsyncResponseService, delivering a…

Python exploit for CVE-2019-2725 targeting Oracle WebLogic Server RCE. Executes arbitrary commands on vulnerable systems for authorized security…

Oracle WebLogic WLS-WSAT Remote Code Execution Exploit (CVE-2017-10271)

Exploit for CVE-2018-2893 targeting Oracle WebLogic Server with remote code execution capabilities for penetration testing and vulnerability…

Exploit for CVE-2018-2628 targeting Oracle WebLogic Server deserialization vulnerability, enabling remote code execution via ysoserial JRMP listener.

oracle weblogic

Proof-of-concept exploit for CVE-2020-2969 targeting unauthorized access to Oracle Database password hashes. Enables security researchers to test and…

Python exploit for CVE-2026-89012, a Dolibarr SQL filter denylist bypass that uses a blind-boolean oracle to extract password hashes and API keys via…

Proof-of-concept exploit for CVE-2026-21004: uses crafted SQLite FTS3/4 MATCH prefix queries as a blind oracle to recover indexed secret data…

Vulnerability in the Oracle WebLogic Server component of Oracle Fusion Middleware (subcomponent: WLS Security). Supported versions that are affected…