Christian Catalano
6 exploits
Active since Dec 2013
Jenkins Plugin for SonarQube <= 3.7 - Authenticated Cleartext Password Exposure via sonar.sonarPassword Parameter
SpagoBI < 4.1 - Authenticated Arbitrary File Upload via Worksheet Designer
CVSS 8.0
SpagoBI < 4.0 - Authenticated Cross-Site Scripting via Document Note
SpagoBI < 4.0 - Authenticated Cross-Site Scripting via Short Document Metadata Description Field
Jenkins 1.523 - Stored Cross-Site Scripting via User Description Field
SpagoBI < 4.1 - Privilege Escalation via AdapterHTTP Script
CVSS 8.8