Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1000 CNY

100.0%

CVE-2017-10366 PoC — Oracle PeopleSoft Products PeopleSoft Enterprise PT PeopleTools组件安全漏洞

Source
Associated Vulnerability
Title:Oracle PeopleSoft Products PeopleSoft Enterprise PT PeopleTools组件安全漏洞 (CVE-2017-10366)
Description:Oracle PeopleSoft Products是美国甲骨文(Oracle)公司的一套企业人力资本管理解决方案,它提供了人力资本管理、财务管理、供应商关系管理等功能。PeopleSoft Enterprise PT PeopleTools是其中的一个用于维护PeopleSoft软件的工具和技术平台组件。 Oracle PeopleSoft Products中的PeopleSoft Enterprise PT PeopleTools组件8.54版本、8.55版本和8.56版本的Performance M
Description
CVE-2017-10366: Oracle PeopleSoft 8.54, 8.55, 8.56 Java deserialization exploit
Readme
# CVE-2017-10366: Oracle PeopleSoft 8.54, 8.55, 8.56 Java deserialization exploit

This script automates the exploitation of a Java deserialization vulnerability
in Oracle PeopleSoft, originally discovered by Vahagn Vardanyan.

This exploit requires ysoserial.jar to generate cross-platform serialized
Java payloads. ysoserial must be in the same directory as this script.

PS: It uses ysoserial-modified.jar, which can be found in https://github.com/pimps/ysoserial-modified/

Copyright 2016-2018, Blaze Information Security
File Snapshot

[4.0K] /data/pocs/94eb356831b79f7268f59e2d350cb22dd94f32ea ├── [3.7K] CVE-2017-10366_peoplesoft.py └── [ 526] README.md 0 directories, 2 files
Shenlong Bot has cached this for you
Remarks
    1. It is advised to access via the original source first.
    2. If the original source is unavailable, please email f.jinxu#gmail.com for a local snapshot (replace # with @).
    3. Shenlong has snapshotted the POC code for you. To support long-term maintenance, please consider donating. Thank you for your support.