
Exploit de prova de conceito para CVE-2022-21587 direcionado ao Oracle E-Business Suite com capacidades de sobrescrita de arquivos e criação de shell.
CVE-2022-21587 POC
file exploit.py will overwrite to file .pl (not recommended for use, will affect the system)
file EBS not overwrite, will create a new shell file
instalar slipit: git clone https://github.com/usdAG/slipit
cd slipit
python3 setup.py sdist
pip3 install --user dist/*
export PATH=/home/yourname/.local/bin:$PATH
instalar uuencode: sudo apt-get install sharutils
Explorar: python3 http|https://example.com