security-misconfiguration

2 articles
sort: new top best
clear filter
0 5/10

A researcher discovered a $1500 deserialization vulnerability in a JSF-based application by identifying unencrypted serialized Java objects in the javax.faces.ViewState parameter, then exploited it using the Jexboss tool to achieve remote code execution via an exposed JMX console.

Ashish Kunwar Jexboss JSF MyFaces Prototype 1.6.1 Bugcrowd Burp Suite Wappalyzer
medium.com · kh4sh3i/bug-bounty-writeups · 22 hours ago · details
0 7/10

This article details a real-world RCE vulnerability chain on Adobe Experience Manager (AEM) 6.1, exploiting exposed Felix Console through dispatcher bypass (CVE-2016-0957), default credentials (admin/admin), and malicious OSGi bundle deployment. The author provides step-by-step methodology for gaining code execution without Java knowledge by using pre-built exploitation tools.

CVE-2016-0957 Adobe Experience Manager AEM Apache Felix Apache Sling OSGi aem_hacker.py aem-rce-bundle Mikhail Egorov 0ang3el Peter Adkins Darkarnium byq
medium.com · devanshbatham/Awesome-Bugbounty-Writeups · 22 hours ago · details