# N/A
## 概述
Primetek Primefaces 5.x 存在加密缺陷,导致远程代码执行漏洞。
## 影响版本
PrimeFaces 5.x
## 细节
该漏洞源于加密机制的薄弱,攻击者可以利用这一缺陷进行远程代码执行。
## 影响
攻击者可以远程执行任意代码,从而控制受影响的应用程序或服务器。
是否为 Web 类漏洞: 是
判断理由:
| # | POC 描述 | 源链接 | 神龙链接 |
|---|---|---|---|
| 1 | Primefaces <= 5.2.21, 5.3.8 or 6.0 - Remote Code Execution Exploit | https://github.com/pimps/CVE-2017-1000486 | POC详情 |
| 2 | Proof of Concept Exploit for PrimeFaces 5.x EL Injection (CVE-2017-1000486) | https://github.com/mogwailabs/CVE-2017-1000486 | POC详情 |
| 3 | cve-2017-1000486 | https://github.com/cved-sources/cve-2017-1000486 | POC详情 |
| 4 | None | https://github.com/Pastea/CVE-2017-1000486 | POC详情 |
| 5 | 😛 Primefaces 5.X EL Injection Exploit (CVE-2017-1000486) | https://github.com/oppsec/pwnfaces | POC详情 |
| 6 | Remote Code Execution exploit for PrimeFaces 5.x - EL Injection (CVE-2017-1000486) | https://github.com/LongWayHomie/CVE-2017-1000486 | POC详情 |
| 7 | Explotación CVE-2017-1000486 | https://github.com/jam620/primefaces | POC详情 |
| 8 | 😛 Primefaces 5.X EL Injection Exploit (CVE-2017-1000486) | https://github.com/000pp/pwnfaces | POC详情 |
| 9 | Primetek Primefaces 5.x is vulnerable to a weak encryption flaw resulting in remote code execution. | https://github.com/projectdiscovery/nuclei-templates/blob/main/http/cves/2017/CVE-2017-1000486.yaml | POC详情 |
| 10 | 😛 Golang project to exploit an EL Injection vulnerability (CVE-2017-1000486) that affects the Primefaces 5.X versions. This project supports SOCKS proxy to prioritize anonymity. | https://github.com/0xdsm/pwnfaces | POC详情 |
暂无评论