Show filters
141 Total Results
Displaying 91-100 of 141
Sort by:
Attacker Value
Unknown

CVE-2019-10073

Disclosure Date: September 11, 2019 (last updated November 08, 2023)
The "Blog", "Forum", "Contact Us" screens of the template "ecommerce" application bundled in Apache OFBiz are weak to Stored XSS attacks. Mitigation: Upgrade to 16.11.06 or manually apply the following commits on branch 16.11: 1858438, 1858543, 1860595 and 1860616
Attacker Value
Unknown

CVE-2018-17200

Disclosure Date: September 11, 2019 (last updated November 08, 2023)
The Apache OFBiz HTTP engine (org.apache.ofbiz.service.engine.HttpEngine.java) handles requests for HTTP services via the /webtools/control/httpService endpoint. This service takes the `serviceContent` parameter in the request and deserializes it using XStream. This `XStream` instance is slightly guarded by disabling the creation of `ProcessBuilder`. However, this can be easily bypassed (and in multiple ways). Mitigation: Upgrade to 16.11.06 or manually apply the following commits on branch 16 r1850017+1850019
Attacker Value
Unknown

CVE-2018-8033

Disclosure Date: December 13, 2018 (last updated November 08, 2023)
In Apache OFBiz 16.11.01 to 16.11.04, the OFBiz HTTP engine (org.apache.ofbiz.service.engine.HttpEngine.java) handles requests for HTTP services via the /webtools/control/httpService endpoint. Both POST and GET requests to the httpService endpoint may contain three parameters: serviceName, serviceMode, and serviceContext. The exploitation occurs by having DOCTYPEs pointing to external references that trigger a payload that returns secret information from the host.
0
Attacker Value
Unknown

CVE-2017-15714

Disclosure Date: January 04, 2018 (last updated November 26, 2024)
The BIRT plugin in Apache OFBiz 16.11.01 to 16.11.03 does not escape user input property passed. This allows for code injection by passing that code through the URL. For example by appending this code "__format=%27;alert(%27xss%27)" to the URL an alert window would execute.
0
Attacker Value
Unknown

CVE-2012-1622

Disclosure Date: October 26, 2017 (last updated November 08, 2023)
Apache OFBiz 10.04.x before 10.04.02 allows remote attackers to execute arbitrary code via unspecified vectors.
0
Attacker Value
Unknown

CVE-2016-6800

Disclosure Date: August 30, 2017 (last updated November 08, 2023)
The default configuration of the Apache OFBiz framework offers a blog functionality. Different users are able to operate blogs which are related to specific parties. In the form field for the creation of new blog articles the user input of the summary field as well as the article field is not properly sanitized. It is possible to inject arbitrary JavaScript code in these form fields. This code gets executed from the browser of every user who is visiting this article. Mitigation: Upgrade to Apache OFBiz 16.11.01.
0
Attacker Value
Unknown

CVE-2016-4462

Disclosure Date: August 30, 2017 (last updated February 15, 2024)
By manipulating the URL parameter externalLoginKey, a malicious, logged in user could pass valid Freemarker directives to the Template Engine that are reflected on the webpage; a specially crafted Freemarker template could be used for remote code execution. Mitigation: Upgrade to Apache OFBiz 16.11.01
0
Attacker Value
Unknown

CVE-2015-3268

Disclosure Date: April 12, 2016 (last updated November 25, 2024)
Cross-site scripting (XSS) vulnerability in the DisplayEntityField.getDescription method in ModelFormField.java in Apache OFBiz before 12.04.06 and 13.07.x before 13.07.03 allows remote attackers to inject arbitrary web script or HTML via the description attribute of a display-entity element.
0
Attacker Value
Unknown

CVE-2016-2170

Disclosure Date: April 12, 2016 (last updated November 08, 2023)
Apache OFBiz 12.04.x before 12.04.06 and 13.07.x before 13.07.03 allow remote attackers to execute arbitrary commands via a crafted serialized Java object, related to the Apache Commons Collections library.
Attacker Value
Unknown

CVE-2015-2475

Disclosure Date: August 15, 2015 (last updated October 05, 2023)
Cross-site scripting (XSS) vulnerability in uddi/search/frames.aspx in the UDDI Services component in Microsoft Windows Server 2008 SP2 and BizTalk Server 2010, 2013 Gold, and 2013 R2 allows remote attackers to inject arbitrary web script or HTML via the search parameter, aka "UDDI Services Elevation of Privilege Vulnerability."
0