Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1000 CNY

100.0%

CVE-2018-3167 PoC — Oracle E-Business Suite Application Management Pack for Oracle E-Business Suite组件安全漏洞

Source
Associated Vulnerability
Title:Oracle E-Business Suite Application Management Pack for Oracle E-Business Suite组件安全漏洞 (CVE-2018-3167)
Description:Oracle E-Business Suite(电子商务套件)是美国甲骨文(Oracle)公司的一套全面集成式的全球业务管理软件。Application Management Pack(AMP)for Oracle E-Business Suite是其中的一个扩展了Oracle Enterprise Manager 10g Grid Control以帮助监测和有效地管理电子商务套件的应用软件管理组件。 Oracle E-Business Suite中的Application Management Pack
Description
Oracle E-Business Suite, Application Management Pack component (User Monitoring subcomponent), is susceptible to blind server-side request forgery. An attacker with network access via HTTP can gain read access to a subset of data, connect to internal services like HTTP-enabled databases, or perform post requests towards internal services which are not intended to be exposed. Affected supported versions are 12.1.3, 12.2.3, 12.2.4, 12.2.5, 12.2.6, and 12.2.7.
File Snapshot

id: CVE-2018-3167 info: name: Oracle E-Business Suite - Blind SSRF author: geeknik severity: ...
Shenlong Bot has cached this for you
Remarks
    1. It is advised to access via the original source first.
    2. If the original source is unavailable, please email f.jinxu#gmail.com for a local snapshot (replace # with @).
    3. Shenlong has snapshotted the POC code for you. To support long-term maintenance, please consider donating. Thank you for your support.