Phying News
Curated security research, vulnerabilities, advisories and tools for practitioners.

[CVE-2013-2165] When EL Injection meets Java Deserialization

blog.viettelcybersecurity.com | vulnerability | CVE-2013-2165 | #zero-day

Summary

0. The storyA target during my pentest was using Java Server Faces (JSF) with an UI framework namely Jboss Richfaces. After exploiting the target using CVE-2013-2165 on Richfaces 4 (covered at my last post), I caught Codewhitesec’s blog post [1] about a new 0-day vulnerability in the Richfaces library.
Published
Collected

original ↗

Related coverage

back