java-gadget-chain. This project contains a Java deserialization vulnerability that is exploitable with some ysoserial payloads, but also contains a custom class that can be leveraged to get command execution upon deserialization.

github.com/dub-flow/java-gadget-chain

Vaya's read on this project

Problem, audience, market, and the verdict — sign in to see it.

Updates

No recent activity.