Back to search
CVE-2011-3600
Published: Nov 26, 2019
Modified: Aug 6, 2024
PUBLISHED
Description
The /webtools/control/xmlrpc endpoint in OFBiz XML-RPC event handler is exposed to External Entity Injection by passing DOCTYPE declarations with executable payloads that discloses the contents of files in the filesystem. In addition, it can also be used to probe for open network ports, and figure out from returned error messages whether a file exists or not. This affects OFBiz 16.11.01 to 16.11.04.
| Vendor | Product | Versions |
|---|---|---|
OFBiz | OFBiz | affected 16.11.01 to 16.11.04 |
References
https://security-tracker.debian.org/tracker/CVE-2011-3600
x_refsource_MISC
https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2011-3600
x_refsource_MISC
https://access.redhat.com/security/cve/cve-2011-3600
x_refsource_MISC
Security Training
Train your team to recognize and prevent security threats with our comprehensive security awareness program.
Start TrainingVulnerability Scanning
Discover vulnerabilities in your applications and infrastructure before attackers do.
Scan Now