CVE-2011-3600
Last modified
CVE-2011-3600 is a high-severity vulnerability rated 7.5/10 on the CVSS scale. The /webtools/control/xmlrpc endpoint in OFBiz XML-RPC event handler is exposed to External Entity Injection by passing DOCTYPE declarations with executable payloads that discloses the contents of files in the filesystem. In addition, it can also be used to probe for open network ports, and figure out from returned error messages whether a file exists or not. EPSS estimates a 15.91% chance of exploitation in the next 30 days.
Description
The /webtools/control/xmlrpc endpoint in OFBiz XML-RPC event handler is exposed to External Entity Injection by passing DOCTYPE declarations with executable payloads that discloses the contents of files in the filesystem. In addition, it can also be used to probe for open network ports, and figure out from returned error messages whether a file exists or not. This affects OFBiz 16.11.01 to 16.11.04.
Metrics
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Apache | Ofbiz | >= 16.11.01, <= 16.11.04 |
References
- https://access.redhat.com/security/cve/cve-2011-3600Third Party Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2011-3600Issue Tracking, Patch, Third Party Advisory
- https://security-tracker.debian.org/tracker/CVE-2011-3600Third Party Advisory
- https://access.redhat.com/security/cve/cve-2011-3600Third Party Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2011-3600Issue Tracking, Patch, Third Party Advisory
- https://security-tracker.debian.org/tracker/CVE-2011-3600Third Party Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2011-3600?
How severe is CVE-2011-3600?
How do I fix CVE-2011-3600?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2011
- CVE-2011-3594The g_markup_escape_text function in the SILC protocol plug-…
- CVE-2011-3595Multiple Cross-site Scripting (XSS) vulnerabilities exist in…5.4
- CVE-2011-3596Polipo before 1.0.4.1 suffers from a DoD vulnerability via s…7.5
- CVE-2011-3597Eval injection vulnerability in the Digest module before 1.1…
- CVE-2011-3598Multiple cross-site scripting (XSS) vulnerabilities in phpPg…
- CVE-2011-3599The Crypt::DSA (aka Crypt-DSA) module 1.17 and earlier for P…
- CVE-2011-3601Buffer overflow in the process_ra function in the router adv…
- CVE-2011-3602Directory traversal vulnerability in device-linux.c in the r…
- CVE-2011-3603The router advertisement daemon (radvd) before 1.8.2 does no…
- CVE-2011-3604The process_ra function in the router advertisement daemon (…
- CVE-2011-3605The process_rs function in the router advertisement daemon (…
- CVE-2011-3606A DOM based cross-site scripting flaw was found in the JBoss…5.4
Are you affected by CVE-2011-3600?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
