WebLogic - CVE-2018-2628
Vulnerability in the Oracle WebLogic Server component of Oracle Fusion Middleware (subcomponent: WLS Core Components).
Affected versions: 10.3.6.0, 12.1.3.0, 12.2.1.2 and 12.2.1.3.
PoC
This vulnerability can be exploited using jas502n's script CVE-2018-2628-Getshell.py
. A working webshell (to be uploaded) can be found on my git, it is massive and looks weird, but as you see in the picture it will be compiled to a smaller shell.
This is probably an error on my end, but I'm too lazy to investigate at the moment.
Note that the shell is one-time-use only, meaning it will be removed once you execute a command.
Last updated