Skip to main content

CVE-2017-1000486

Description

Primetek Primefaces 5.x is vulnerable to a weak encryption flaw resulting in remote code execution

nvd
CVE ID: CVE-2017-1000486
Base Score: 9.8
Base Severity: CRITICAL
Vector String:CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Proof Of Concept

Nuclei Templates for CVE-2017-1000486
pimps

Primefaces <= 5.2.21, 5.3.8 or 6.0 - Remote Code Execution Exploit

Refrence: GitHub

mogwailabs

Proof of Concept Exploit for PrimeFaces 5.x EL Injection (CVE-2017-1000486)

Refrence: GitHub

cved-sources

cve-2017-1000486

Refrence: GitHub

Pastea

Refrence: GitHub

oppsec

😛 Primefaces 5.X EL Injection Exploit (CVE-2017-1000486)

Refrence: GitHub

LongWayHomie

Remote Code Execution exploit for PrimeFaces 5.x - EL Injection (CVE-2017-1000486)

Refrence: GitHub

jam620

Explotación CVE-2017-1000486

Refrence: GitHub

Refrence: NVD