Skip to content
Exploitation toolkit for RichFaces
Java
Branch: master
Clone or download

Latest commit

Latest commit 583f553 Mar 7, 2020

Files

Permalink
Type Name Latest commit message Commit time
Failed to load latest commit information.
bin Add files via upload Mar 6, 2020
src
README.MD Update README.MD Mar 6, 2020
pom.xml Add files via upload Mar 6, 2020

README.MD

Richsploit

Richsploit: Exploitation toolkit for RichFaces.

Overview

Richsploit can be used to exploit JSF endpoints using RichFaces. All versions from 3.1.0 and higher are vulnerable.

usage: Richsploit
 -e,--exploit    0: CVE-2013-2165
                 1: CVE-2015-0279
                 2: CVE-2018-12532
                 3: CVE-2018-12533
                 4: CVE-2018-14667
 -p,--payload    The file containing serialized object
                 (CVE-2013-2165), or
                 Shell command to execute (all other CVE's)
 -u,--url        URL of richfaces application, i.e.
                 http://example.com/app for RF4.x and
                 http://example.com/app/a4j/g/3_3_3.Final for RF3.x
 -v,--version    Richfaces branch, either 3 or 4

For more information about how to use the tool, please see this blog post.

You can’t perform that action at this time.