Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1000 CNY

100.0%

CVE-2017-10366 PoC — Oracle PeopleSoft Products PeopleSoft Enterprise PT PeopleTools组件安全漏洞

Source
Associated Vulnerability
Title:Oracle PeopleSoft Products PeopleSoft Enterprise PT PeopleTools组件安全漏洞 (CVE-2017-10366)
Description:Vulnerability in the PeopleSoft Enterprise PT PeopleTools component of Oracle PeopleSoft Products (subcomponent: Performance Monitor). Supported versions that are affected are 8.54, 8.55 and 8.56. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise PeopleSoft Enterprise PT PeopleTools. Successful attacks of this vulnerability can result in takeover of PeopleSoft Enterprise PT PeopleTools. CVSS 3.0 Base Score 9.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).
Description
CVE-2017-10366: Oracle PeopleSoft 8.54, 8.55, 8.56 Java deserialization exploit
Readme
# CVE-2017-10366: Oracle PeopleSoft 8.54, 8.55, 8.56 Java deserialization exploit

This script automates the exploitation of a Java deserialization vulnerability
in Oracle PeopleSoft, originally discovered by Vahagn Vardanyan.

This exploit requires ysoserial.jar to generate cross-platform serialized
Java payloads. ysoserial must be in the same directory as this script.

PS: It uses ysoserial-modified.jar, which can be found in https://github.com/pimps/ysoserial-modified/

Copyright 2016-2018, Blaze Information Security
File Snapshot

[4.0K] /data/pocs/94eb356831b79f7268f59e2d350cb22dd94f32ea ├── [3.7K] CVE-2017-10366_peoplesoft.py └── [ 526] README.md 0 directories, 2 files
Shenlong Bot has cached this for you
Remarks
    1. It is advised to access via the original source first.
    2. Local POC snapshots are reserved for subscribers — if the original source is unavailable, the local mirror is part of the paid plan.
    3. Mirroring, verifying, and maintaining this POC archive takes ongoing effort, so local snapshots are a paid feature. Your subscription keeps the archive online — thank you for the support. View subscription plans →