Sploitus

CVE-2018-8033

1 known exploit for CVE-2018-8033

In Apache OFBiz 16.11.01 to 16.11.04, the OFBiz HTTP engine (org.apache.ofbiz.service.engine.HttpEngine.java) handles requests for HTTP services via the /webtools/control/httpService endpoint. Both POST and GET requests to the httpService endpoint may contain three parameters: serviceName, serviceMode, and serviceContext. The exploitation occurs by having DOCTYPEs pointing to external references that trigger a payload that returns secret information from the host.

Affected products
Apache Ofbiz
Apache Ofbiz
≤ 16.11.04
CVSS 3.0
7.5 HIGH
EPSS
59.6% (99th percentile)
Weakness
CWE-200
NVD status
Modified
Published
2018-12-13
CVE-2018-8033 at NVD
Authoritative description, scoring and affected products

1 known exploit for CVE-2018-8033

Proof-of-concept code and exploit modules indexed by Sploitus