Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1310 CNY

100%

CVE-2017-10352 PoC — Oracle Fusion Middleware Oracle WebLogic Server组件安全漏洞

Source
Associated Vulnerability
Title:Oracle Fusion Middleware Oracle WebLogic Server组件安全漏洞 (CVE-2017-10352)
Description:Vulnerability in the Oracle WebLogic Server component of Oracle Fusion Middleware (subcomponent: WLS - Web Services). The supported version that is affected are 10.3.6.0.0, 12.1.3.0.0, 12.2.1.1.0, 12.2.1.2.0 and 12.2.1.3.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle WebLogic Server. While the vulnerability is in Oracle WebLogic Server, attacks may significantly impact additional products. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle WebLogic Server as well as unauthorized update, insert or delete access to some of Oracle WebLogic Server accessible data and unauthorized read access to a subset of Oracle WebLogic Server accessible data. CVSS 3.0 Base Score 9.9 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:L/A:H).
Description
CVE-2017-10352 CVE-2017-10271 weblogic-XMLDecoder
Readme
******本软件仅限用于学习交流禁止用于任何非法行为****** 
#Weblogic-XMLDecoder-GUI CVE-2017-10352
基于python GUI 实验作品 主要功能针对对weblogic XMLDecoder 造成的反序列化漏洞的利用,开发目的熟悉python tkinter 类库以及ttk扩展的使用
稍后会封装为windows下可执行文件主要针对的漏洞为CVE-2017-10271  CVE-2017-10352,为神马两个漏洞因为oracle官方第一次的布丁没打好,下图为mac
下的截图效果一般


![image](https://github.com/bigsizeme/weblogic-XMLDecoder/blob/master/screenshot/6.png)

P.S: 提交于中华民族的传统节日大年初三,本打算大年三十做个了结,但年夜饭做的有点累了,一拖就是初三了(有图为证)。

![image](https://github.com/bigsizeme/weblogic-XMLDecoder/blob/master/screenshot/3.JPG)

![image](https://github.com/bigsizeme/weblogic-XMLDecoder/blob/master/screenshot/4.JPG)

特别感谢  https://github.com/s3xy/CVE-2017-10271  在此基础上做了修改

GitHub 搬运工

forked from https://github.com/s3xy/CVE-2017-10271



File Snapshot

Log in to view the POC file snapshot cached by Shenlong Bot

Log in to view
Remarks
    1. It is advised to access via the original source first.
    2. Local POC snapshots are reserved for subscribers — if the original source is unavailable, the local mirror is part of the paid plan.
    3. Mirroring, verifying, and maintaining this POC archive takes ongoing effort, so local snapshots are a paid feature. Your subscription keeps the archive online — thank you for the support. View subscription plans →