mirror of
https://github.com/gobysec/GobyVuls.git
synced 2025-06-20 09:50:49 +00:00
add CVE-2018-8033
This commit is contained in:
parent
c98d280949
commit
13019f0d37
BIN
OFBiz/CVE-2018-8033/CVE-2018-8033.gif
Normal file
BIN
OFBiz/CVE-2018-8033/CVE-2018-8033.gif
Normal file
Binary file not shown.
After Width: | Height: | Size: 155 KiB |
11
OFBiz/CVE-2018-8033/README.md
Normal file
11
OFBiz/CVE-2018-8033/README.md
Normal file
@ -0,0 +1,11 @@
|
||||
# CVE-2018-8033 Apache OFBiz XXE File Read
|
||||
|
||||
In Apache OFBiz 16.11.01 to 16.11.04, the OFBiz HTTP engine (org.apache.ofbiz.service.engine.HttpEngine.java) handles requests for HTTP services via the /webtools/control/httpService endpoint. Both POST and GET requests to the httpService endpoint may contain three parameters: serviceName, serviceMode, and serviceContext. The exploitation occurs by having DOCTYPEs pointing to external references that trigger a payload that returns secret information from the host.
|
||||
|
||||
**Affected version**: Apache OFBiz 16.11.01 - 16.11.04
|
||||
|
||||
**[FOFA](https://fofa.so/result?q=header%3D%22Set-Cookie%3A+OFBiz.Visitor%22&qbase64=aGVhZGVyPSJTZXQtQ29va2llOiBPRkJpei5WaXNpdG9yIg%3D%3D&file=&file=) query rule**: header="Set-Cookie: OFBiz.Visitor"
|
||||
|
||||
# Demo
|
||||
|
||||

|
Loading…
x
Reference in New Issue
Block a user