Oracle PeopleSoft Remote Code Execution: Blind XXE to SYSTEM Shell
Common Information
Type Value
UUID bbd0c791-169b-44e3-adc3-7f0d1a02c57b
Fingerprint 25f81199296420b2
Analysis status DONE
Considered CTI value 2
Text language
Published May 17, 2017, midnight
Added to db Jan. 18, 2023, 10:47 p.m.
Last updated Nov. 17, 2024, 6:49 p.m.
Headline Update
Title Oracle PeopleSoft Remote Code Execution: Blind XXE to SYSTEM Shell
Detected Hints/Tags/Attributes 38/1/38
Attributes
Details Type #Events CTI Value
Details CVE 1
cve-2013-3800
Details CVE 1
cve-2013-3821
Details CVE 1
cve-2017-3548
Details Domain 24
website.com
Details Domain 150
www.w3.org
Details Domain 32
schemas.xmlsoap.org
Details Domain 4
xml.apache.org
Details Domain 3
www.ambionics.io
Details Domain 1
colorama.fore.green
Details Domain 2
colorama.fore.red
Details Domain 1
colorama.fore.blue
Details Domain 138
java.io
Details Domain 3
self.session.post
Details Domain 1
self.post
Details Domain 1
colorama.style
Details File 31
schemas.xml
Details File 1
apache.pl
Details File 9
packages.url
Details File 2
colorama.ini
Details File 20
shell.jsp
Details File 7
self.url
Details File 2
self.ini
Details File 1
signon.html
Details File 2
self.ps
Details File 1
%s.jsp
Details File 1
portletentityregistry.xml
Details File 1
handlers.log
Details IPv4 1441
127.0.0.1
Details Url 1
http://website.com/pspc/services.
Details Url 1
http://website.com/pspc/services/adminservice.
Details Url 50
http://www.w3.org/2001/xmlschema-instance
Details Url 1
http://127.0.0.1/integrics/enswitch/api
Details Url 22
http://www.w3.org/2001/xmlschema
Details Url 24
http://schemas.xmlsoap.org/soap/envelope
Details Url 1
http://xml.apache.org/axis/wsdd
Details Url 1
http://xml.apache.org/axis/wsdd/providers/java
Details Url 10
http://schemas.xmlsoap.org/soap/encoding
Details Url 1
https://www.ambionics.io/blog/oracle-peoplesoft-xxe-to-rce