jexboss

1 article
sort: new top best
clear filter
0 5/10

A researcher discovered a $1500 deserialization vulnerability in a JSF-based application by identifying unencrypted serialized Java objects in the javax.faces.ViewState parameter, then exploited it using the Jexboss tool to achieve remote code execution via an exposed JMX console.

Ashish Kunwar Jexboss JSF MyFaces Prototype 1.6.1 Bugcrowd Burp Suite Wappalyzer
medium.com · kh4sh3i/bug-bounty-writeups · 23 hours ago · details