CVE-2011-3600
HIGH EXPLOITED NUCLEIOFBiz <16.11.04 - SSRF
Title source: llmDescription
The /webtools/control/xmlrpc endpoint in OFBiz XML-RPC event handler is exposed to External Entity Injection by passing DOCTYPE declarations with executable payloads that discloses the contents of files in the filesystem. In addition, it can also be used to probe for open network ports, and figure out from returned error messages whether a file exists or not. This affects OFBiz 16.11.01 to 16.11.04.
Nuclei Templates (1)
Apache OFBiz - XML External Entity Injection
HIGHVERIFIEDby daffainfo,pikpikcu
Shodan:
http.html:"ofbiz" || ofbiz.visitor=
FOFA:
body="ofbiz" || app="apache_ofbiz"
References (5)
Scores
CVSS v3
7.5
EPSS
0.6558
EPSS Percentile
98.5%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Details
VulnCheck KEV
2023-11-21
CWE
CWE-611
Status
published
Products (1)
apache/ofbiz
16.11.01 - 16.11.04
Published
Nov 26, 2019
Tracked Since
Feb 18, 2026