Sploitus

Exploit for Code Injection in Redhat Richfaces

githubexploit · 2026-08-31

Exploit Code

README37 lines
## https://sploitus.com/exploit?id=51F666E2-6D5B-5764-A765-3B756DA448E4
# CVE-2018-14667-Lab
POC for the exploitation of CVE-2018-14667

PREREQUISITES

Demo App From : http://downloads.jboss.org/richfaces/releases/3.3.X/3.3.4.Final/richfaces-examples-3.3.4.Final.zip

Jboss 5.1.0.GA from JBOSS download archive : https://repository.jboss.org/sourceforge/

Jdk-6u45-linux-x64 from JAVA archive : https://www.oracle.com/java/technologies/javase-java-archive-javase6-downloads.html



EXPLOITATION

1 - Install Maven and modify Main.java with the command to execute 



2 - Run Runer.bash



3- Before sending the payload, visit the index page of the photoalbum lab



4 - The command is executed succesfully





NOTE 

The exploit was taken from here and modified to adapt to the JBOSS App Server serialization  : https://pastebin.com/raw/YRKdatWv