Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2018-8033

Опубликовано: 13 дек. 2018
Источник: nvd
CVSS3: 7.5
CVSS2: 5
EPSS Критический

Описание

In Apache OFBiz 16.11.01 to 16.11.04, the OFBiz HTTP engine (org.apache.ofbiz.service.engine.HttpEngine.java) handles requests for HTTP services via the /webtools/control/httpService endpoint. Both POST and GET requests to the httpService endpoint may contain three parameters: serviceName, serviceMode, and serviceContext. The exploitation occurs by having DOCTYPEs pointing to external references that trigger a payload that returns secret information from the host.

Уязвимые конфигурации

Конфигурация 1
cpe:2.3:a:apache:ofbiz:*:*:*:*:*:*:*:*
Версия от 16.11.01 (включая) до 16.11.04 (включая)

EPSS

Процентиль: 100%
0.9208
Критический

7.5 High

CVSS3

5 Medium

CVSS2

Дефекты

CWE-200

Связанные уязвимости

CVSS3: 7.5
github
больше 3 лет назад

In Apache OFBiz 16.11.01 to 16.11.04, the OFBiz HTTP engine (org.apache.ofbiz.service.engine.HttpEngine.java) handles requests for HTTP services via the /webtools/control/httpService endpoint. Both POST and GET requests to the httpService endpoint may contain three parameters: serviceName, serviceMode, and serviceContext. The exploitation occurs by having DOCTYPEs pointing to external references that trigger a payload that returns secret information from the host.

EPSS

Процентиль: 100%
0.9208
Критический

7.5 High

CVSS3

5 Medium

CVSS2

Дефекты

CWE-200