.. / CVE-2017-3506

Exploit for Oracle Fusion Middleware Weblogic Server - Remote OS Command Execution (CVE-2017-3506)

Description:

The Oracle WebLogic Server component of Oracle Fusion Middleware (Web Services) versions 10.3.6.0, 12.1.3.0, 12.2.1.0, 12.2.1.1 and 12.2.1.2 is susceptible to a difficult to exploit vulnerability that could allow unauthenticated attackers with network access via HTTP to compromise Oracle WebLogic Server.

Nuclei Template

View the template here CVE-2017-3506.yaml

Validate with Nuclei

echo "$URL" | nuclei -t ~/nuclei-templates/http/cves/2017/CVE-2017-3506.yaml
Copy

References:

http://www.oracle.com/technetwork/security-advisory/cpuapr2017-3236618.html
https://nvd.nist.gov/vuln/detail/CVE-2017-3506
https://hackerone.com/reports/810778
http://www.securitytracker.com/id/1038296
https://github.com/CVEDB/top