非影资讯
面向安全从业者的中英双语安全研究与漏洞情报精选。

[CVE-2013-2165] When EL Injection meets Java Deserialization

blog.viettelcybersecurity.com | 漏洞 | CVE-2013-2165 | #zero-day

摘要

0. The storyA target during my pentest was using Java Server Faces (JSF) with an UI framework namely Jboss Richfaces. After exploiting the target using CVE-2013-2165 on Richfaces 4 (covered at my last post), I caught Codewhitesec’s blog post [1] about a new 0-day vulnerability in the Richfaces library.
发布时间
收录时间

原文 ↗

相关内容

返回