
Python एक्सप्लॉइट स्क्रिप्ट है CVE-2017-10271 के लिए, जो Oracle WebLogic Server के WLS-WSAT घटक को लक्षित करती है। आउटपुट के साथ कमांड निष्पादन और सीधे JSP शेल अपलोड का समर्थन करती है, जिससे बिना प्रमाणीकरण के रिमोट समझौता संभव होता है।
Weblogic wls-wsat घटक डिसीरियलाइज़ेशन भेद्यता (CVE-2017-10271) शोषण स्क्रिप्ट, https://github.com/s3xy/CVE-2017-10271 से संदर्भित और संशोधित।
उपयोग विधि और पैरामीटर
usage: weblogic_wls_wsat_exp.py [-h] -t TARGET [-c CMD] [-o OUTPUT] [-s SHELL]
optional arguments:
-h, --help show this help message and exit
-t TARGET, --target TARGET
weblogic ip and port(eg -> 172.16.80.131:7001)
-c CMD, --cmd CMD command to execute,default is "id"
-o OUTPUT, --output OUTPUT
output file name,default is output.txt
-s SHELL, --shell SHELL
local jsp file name to upload,and set -o xxx.jsp