Show filters
141 Total Results
Displaying 81-90 of 141
Sort by:
Attacker Value
Unknown
CVE-2020-13923
Disclosure Date: July 15, 2020 (last updated February 21, 2025)
IDOR vulnerability in the order processing feature from ecommerce component of Apache OFBiz before 17.12.04
0
Attacker Value
Unknown
CVE-2020-12009
Disclosure Date: June 18, 2020 (last updated February 21, 2025)
A specially crafted communication packet sent to the affected device could cause a denial-of-service condition due to a deserialization vulnerability. This affects: Mitsubishi Electric MC Works64 Version 4.02C (10.95.208.31) and earlier, all versions; Mitsubishi Electric MC Works32 Version 3.00A (9.50.255.02); ICONICS GenBroker64, Platform Services, Workbench, FrameWorX Server v10.96 and prior; ICONICS GenBroker32 v9.5 and prior.
0
Attacker Value
Unknown
CVE-2019-0235
Disclosure Date: April 30, 2020 (last updated February 21, 2025)
Apache OFBiz 17.12.01 is vulnerable to some CSRF attacks.
0
Attacker Value
Unknown
CVE-2019-12425
Disclosure Date: April 30, 2020 (last updated February 21, 2025)
Apache OFBiz 17.12.01 is vulnerable to Host header injection by accepting arbitrary host
0
Attacker Value
Unknown
CVE-2020-1943
Disclosure Date: April 01, 2020 (last updated February 21, 2025)
Data sent with contentId to /control/stream is not sanitized, allowing XSS attacks in Apache OFBiz 16.11.01 to 16.11.07.
0
Attacker Value
Unknown
CVE-2019-12426
Disclosure Date: February 06, 2020 (last updated November 08, 2023)
an unauthenticated user could get access to information of some backend screens by invoking setSessionLocale in Apache OFBiz 16.11.01 to 16.11.06
0
Attacker Value
Unknown
CVE-2011-3600
Disclosure Date: November 26, 2019 (last updated November 27, 2024)
The /webtools/control/xmlrpc endpoint in OFBiz XML-RPC event handler is exposed to External Entity Injection by passing DOCTYPE declarations with executable payloads that discloses the contents of files in the filesystem. In addition, it can also be used to probe for open network ports, and figure out from returned error messages whether a file exists or not. This affects OFBiz 16.11.01 to 16.11.04.
0
Attacker Value
Unknown
CVE-2015-9499
Disclosure Date: October 22, 2019 (last updated November 27, 2024)
The Showbiz Pro plugin through 1.7.1 for WordPress has PHP code execution by uploading a .php file within a ZIP archive.
0
Attacker Value
Unknown
CVE-2019-0189
Disclosure Date: September 11, 2019 (last updated November 08, 2023)
The java.io.ObjectInputStream is known to cause Java serialisation issues. This issue here is exposed by the "webtools/control/httpService" URL, and uses Java deserialization to perform code execution. In the HttpEngine, the value of the request parameter "serviceContext" is passed to the "deserialize" method of "XmlSerializer". Apache Ofbiz is affected via two different dependencies: "commons-beanutils" and an out-dated version of "commons-fileupload" Mitigation: Upgrade to 16.11.06 or manually apply the commits from OFBIZ-10770 and OFBIZ-10837 on branch 16
0
Attacker Value
Unknown
CVE-2019-10074
Disclosure Date: September 11, 2019 (last updated November 08, 2023)
An RCE is possible by entering Freemarker markup in an Apache OFBiz Form Widget textarea field when encoding has been disabled on such a field. This was the case for the Customer Request "story" input in the Order Manager application. Encoding should not be disabled without good reason and never within a field that accepts user input. Mitigation: Upgrade to 16.11.06 or manually apply the following commit on branch 16.11: r1858533
0