Java Jsf Viewstate Deserialization

How to identify and exploit Java JSF ViewState deserialization vulnerabilities in web applications. Use this skill whenever the user mentions JSF, ViewState, Java web applications, deserialization attacks, .faces files, or wants to test for RCE through ViewState manipulation. This is critical for pentesting Java-based web applications using JSF frameworks.

abelrguezr Updated

File contents

abelrguezr/hacktricks-skills/tree/main/skills/pentesting-web/deserialization/java-jsf-viewstate-.faces-deserialization commit c7b34934df

Frequently asked questions

npx skillmds@latest add abelrguezr/java-jsf-viewstate-deserialization