The /webtools/control/xmlrpc endpoint in OFBiz XML-RPC event handler is exposed to External Entity Injection by passing DOCTYPE declarations with executable payloads that discloses the contents of files in the filesystem. In addition, it can also be used to probe for open network ports, and figure out from returned error messages whether a file exists or not. This affects OFBiz 16.11.01 to 16.11.04.
Metrics
Affected Vendors & Products
References
History
No history.
MITRE
Status: PUBLISHED
Assigner: redhat
Published: 2019-11-26T00:07:23
Updated: 2024-08-06T23:37:48.424Z
Reserved: 2011-09-21T00:00:00
Link: CVE-2011-3600
Vulnrichment
No data.
NVD
Status : Modified
Published: 2019-11-26T01:15:10.647
Modified: 2023-02-13T04:32:39.690
Link: CVE-2011-3600
Redhat