weblogic-panel: Weblogic Login Panel

日期: 2025-09-01 | 影响软件: weblogicpanel | POC: 已公开

漏洞描述

shodan-query: product:"Oracle Weblogic"

PoC代码[已公开]

id: weblogic-panel

info:
  name: Weblogic Login Panel
  author: bing0o,meme-lord
  severity: info
  verified: true
  description: |
    shodan-query: product:"Oracle Weblogic"

set:
  randstr: randomLowercase(10)
rules:
  r0:
    request:
      method: GET
      path: /console/login/LoginForm.jsp
    expression: |
      response.status == 200 && ("WebLogic Server Version: (.*?)<".bmatches(response.body) || "WebLogic Server 版本: (.*?)<".bmatches(response.body))
  r1:
    request:
      method: GET
      path: /{{randstr}}
    expression: |
      response.status == 404 &&
      response.body.bcontains(b'Error 404--Not Found') &&
      response.body.bcontains(b'From RFC 2068')
expression: r0() || r1()

相关漏洞推荐