CVE-2011-3600
HIGH EXPLOITED NUCLEIApache OFBiz 16.11.01-16.11.04 - XML External Entity Injection via XML-RPC Endpoint
Title source: llmExploitation Summary
CVE-2011-3600 has been observed exploited in the wild (reported by VulnCheck KEV). A Nuclei detection template is also available.
Description
The /webtools/control/xmlrpc endpoint in OFBiz XML-RPC event handler is exposed to External Entity Injection by passing DOCTYPE declarations with executable payloads that discloses the contents of files in the filesystem. In addition, it can also be used to probe for open network ports, and figure out from returned error messages whether a file exists or not. This affects OFBiz 16.11.01 to 16.11.04.
Nuclei Templates (1)
Apache OFBiz - XML External Entity Injection
HIGHVERIFIEDby daffainfo,pikpikcu
Shodan:
http.html:"ofbiz" || ofbiz.visitor=
FOFA:
body="ofbiz" || app="apache_ofbiz"
References (5)
Core 5
Core References
Third Party Advisory x_refsource_misc
https://security-tracker.debian.org/tracker/CVE-2011-3600
Issue Tracking, Patch, Third Party Advisory x_refsource_misc
https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2011-3600
Third Party Advisory x_refsource_misc
https://access.redhat.com/security/cve/cve-2011-3600
Mailing List x_refsource_misc
https://lists.apache.org/thread.html/7793319ae80ec350f7b82a8763460944f120ebe447f14a12155d0550%40%3Ccommits.ofbiz.apache.org%3E
Various Sources x_refsource_confirm
http://mail-archives.apache.org/mod_mbox/ofbiz-user/201810.mbox/%3Cfad45546-af86-0293-9ea7-014553474b30%40apache.org%3E
Scores
CVSS v3
7.5
EPSS
0.7176
EPSS Percentile
98.8%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Details
VulnCheck KEV
2023-11-21
CWE
CWE-611
Status
published
Products (1)
apache/ofbiz
16.11.01 - 16.11.04
Published
Nov 26, 2019
Tracked Since
Feb 18, 2026