WebLogic CoordinatorPortType 远程代码执行漏洞(CVE-2017-10271)

2023-06-08 WebLogic PoC No

Description

WebLogic Server是其中的一个适用于云环境和传统环境的应用服务器组件。由于WebLogic在部署过程中默认启用了WLS WebService组件,此组件使用了XMLDecoder来解析序列化数据,攻击者可以通过构造恶意的XML文件来实现远程命令执行,可能导致攻击者在服务器端任意执行代码,进而控制整个web服务器。

PoC

None yet. Search at https://trap.biu.life/?ref=rss

Related Vulnerabilities