Sploitus

Exploit for Oracle WebLogic Server Apache Connector POST buffer overflow

saint Β· 2008-07-25

Exploit Code

MARKDOWN32 lines
## https://sploitus.com/exploit?id=SAINT:6763DC454040C45562777CCC7CC949A0
Added: 07/25/2008  
CVE: [CVE-2008-3257](<https://vulners.com/cve/CVE-2008-3257>)  
BID: [30273](<http://www.securityfocus.com/bid/30273>)  
OSVDB: [47096](<http://www.osvdb.org/47096>)  


### Background

[Oracle WebLogic Server](<http://www.bea.com/framework.jsp?CNT=index.htm&FP=/content/products/weblogic/>) (formerly BEA WebLogic Server) is a Java web application platform. 

### Problem

A buffer overflow in the Apache Connector for WebLogic Server allows remote attackers to execute arbitrary commands by sending a long, specially crafted POST request. 

### Resolution

Apply a fix when available. 

### References

<http://secunia.com/advisories/31146/>  


### Limitations

Exploit works on WebLogic Server 10.0. On Windows Server 2003, patch KB933729 (rpcrt4.dll version 5.2.3790.4115) must be installed. 

### Platforms

Windows 2000  
Windows Server 2003