Antonio Scibilia
8 exploits
Active since Apr 2021
Knowage < 7.4 - SQL Injection via 'par_year' Parameter in Document Execution URL Analytics Driver
CVSS 8.8
Knowage Suite < 7.4 - Reflected Cross-Site Scripting via EXEC_FROM Parameter
CVSS 5.4
Knowage < 7.4 - Stored HTML Injection via LABEL and NAME Parameters
CVSS 4.8
Knowage Suite < 7.4 - Cross-Site Scripting via SBI_HOST Parameter
CVSS 6.1
Knowage Suite 7.3 - Stored Cross-Site Scripting via Surname Parameter
CVSS 5.4
Knowage Suite 7.3 - Stored Cross-Site Scripting via Document Notes 'nota' Parameter
CVSS 5.4
Knowage Suite 7.3 - Unauthenticated Reflected Cross-Site Scripting via AdapterHTTP TargetService Parameter
CVSS 6.1
Knowage Suite 7.3 - Stored Client-Side Template Injection via Name Parameter
CVSS 5.4