漏洞描述 【漏洞对象】Apache OFBiz 【漏洞描述】 Apache OFBiz全称是The ApacheOpen For BusinessProject。是开放的电子商务平台,是一个非常著名的开源项目,提供了创建基于最新的J2EE/XML规范和技术标准,构建大中型企业级、快平台、跨数据库、跨应用服务器的多层、分布式电子商务类WEB应用系统的框架。而在/webtools/control/xmlrpc页面由于没有禁用外部实体,攻击者可以通过提交xml实现任意文件读取。
相关漏洞推荐 CVE-2018-8033: Apache OFBiz XXE POC 2025-09-01 | Apache OFBiz XXE injection (file disclosure) exploit for Apache OFBiz 16.11.04 CVE-2020-9496: Apache OFBiz XML-RPC Java Deserialization POC 2025-09-01 | Apache OFBiz XML-RPC request are vulnerable to unsafe deserialization and Cross-Site Scripting issues in Apache O... CVE-2021-29200: Apache OFBiz < 17.12.07 - Arbitrary Code Execution POC 2025-09-01 | Apache OFBiz Apache OFBiz has unsafe deserialization prior to 17.12.07 version An unauthenticated user can perfor... CVE-2018-1000600: Pre-auth Fully-responded SSRF POC 2025-09-01 | Pre-auth A exposure of sensitive information vulnerability exists in Jenkins GitHub Plugin 1.29.1 and earlier... CVE-2018-1000861: Jenkins 2.138 Remote Command Execution POC 2025-09-01 | Jenkins A code execution vulnerability exists in the Stapler web framework used by Jenkins 2.153 and earlier...