Public exploit available
Public proof-of-concept or exploit code exists (ExploitDB / Metasploit / Nuclei).

CVE-2011-3600XML External Entity (XXE) Injection in Apache Ofbiz

Severity
7.5HIGHNVD
EPSS
65.6%
top 1.50%
CISA KEV
Not in KEV
Exploit
PoC available
Public exploit / PoC exists
Affected products
Timeline
PublishedNov 26
Latest updateApr 22

Description

The /webtools/control/xmlrpc endpoint in OFBiz XML-RPC event handler is exposed to External Entity Injection by passing DOCTYPE declarations with executable payloads that discloses the contents of files in the filesystem. In addition, it can also be used to probe for open network ports, and figure out from returned error messages whether a file exists or not. This affects OFBiz 16.11.01 to 16.11.04.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:NExploitability: 3.9 | Impact: 3.6

Affected Packages2 packages

NVDapache/ofbiz16.11.0116.11.04
CVEListV5ofbiz/ofbiz16.11.01 to 16.11.04

Patches

🔴Vulnerability Details

4
GHSA
GHSA-88hg-2f8p-pv3w: The /webtools/control/xmlrpc endpoint in OFBiz XML-RPC event handler is exposed to External Entity Injection by passing DOCTYPE declarations with exec2022-04-22
OSV
CVE-2011-3600: The /webtools/control/xmlrpc endpoint in OFBiz XML-RPC event handler is exposed to External Entity Injection by passing DOCTYPE declarations with exec2019-11-26
CVEList
CVE-2011-3600: The /webtools/control/xmlrpc endpoint in OFBiz XML-RPC event handler is exposed to External Entity Injection by passing DOCTYPE declarations with exec2019-11-26
VulnCheck
Apache OFBiz Improper Restriction of XML External Entity Reference2011

💥Exploits & PoCs

1
Nuclei
Apache OFBiz - XML External Entity Injection

📋Vendor Advisories

2
Red Hat
XML-RPC SAX parser information exposure2010-02-06
Apache
Apache ofbiz: CVE-2011-3600

💬Community

2
Bugzilla
CVE-2011-3600 XML-RPC SAX parser information exposure [fedora-14]2011-10-08
Bugzilla
CVE-2011-3600 XML-RPC SAX parser information exposure2011-05-18
CVE-2011-3600 — XML External Entity (XXE) Injection | cvebase