Skip to content
Exploitation toolkit for RichFaces
Branch: master
Clone or download

Latest commit

Latest commit 583f553 Mar 7, 2020


Type Name Latest commit message Commit time
Failed to load latest commit information.
bin Add files via upload Mar 6, 2020
README.MD Update README.MD Mar 6, 2020
pom.xml Add files via upload Mar 6, 2020



Richsploit: Exploitation toolkit for RichFaces.


Richsploit can be used to exploit JSF endpoints using RichFaces. All versions from 3.1.0 and higher are vulnerable.

usage: Richsploit
 -e,--exploit    0: CVE-2013-2165
                 1: CVE-2015-0279
                 2: CVE-2018-12532
                 3: CVE-2018-12533
                 4: CVE-2018-14667
 -p,--payload    The file containing serialized object
                 (CVE-2013-2165), or
                 Shell command to execute (all other CVE's)
 -u,--url        URL of richfaces application, i.e.
        for RF4.x and
        for RF3.x
 -v,--version    Richfaces branch, either 3 or 4

For more information about how to use the tool, please see this blog post.

You can’t perform that action at this time.