CVE-2018-8033
In Apache OFBiz 16.11.01 to 16.11.04, the OFBiz HTTP engine (org.apache.ofbiz.service.engine.HttpEngine.java) handles requests for HTTP services via the /webtools/control/httpService endpoint. Both POST and GET requests to the httpService endpoint may contain three parameters: serviceName, serviceMode, and serviceContext. The exploitation occurs by having DOCTYPEs pointing to external references that trigger a payload that returns secret information from the host.
- Affected products
- Apache Ofbiz
- Apache Ofbiz
- ≤ 16.11.04
- CVSS 3.0
- 7.5 HIGH
- EPSS
- 59.6% (99th percentile)
- Weakness
- CWE-200
- NVD status
- Modified
- Published
- 2018-12-13
CVE-2018-8033 at NVD
1 known exploit for CVE-2018-8033
Proof-of-concept code and exploit modules indexed by Sploitus