Gianluca Palma
15 exploits
Active since Oct 2020
WSO2 Enterprise Integrator < 6.6.0 - Stored Cross-Site Scripting in BPMN Explorer Tasks
CVSS 5.4
audimexee < 14.1.1 - Reflected Cross-Site Scripting via Action, Cargo, or Panel Parameters
CVSS 5.4
audimexee < 14.1.1 - SQL Injection via Documents Component object_path Parameter
CVSS 8.8
Knowage < 7.4 - SQL Injection via 'par_year' Parameter in Document Execution URL Analytics Driver
CVSS 8.8
Knowage Suite < 7.4 - Reflected Cross-Site Scripting via EXEC_FROM Parameter
CVSS 5.4
Knowage < 7.4 - Stored HTML Injection via LABEL and NAME Parameters
CVSS 4.8
Knowage Suite < 7.4 - Cross-Site Scripting via SBI_HOST Parameter
CVSS 6.1
Knowage Suite 7.3 - Stored Cross-Site Scripting via Surname Parameter
CVSS 5.4
Knowage Suite 7.3 - Stored Cross-Site Scripting via Document Notes 'nota' Parameter
CVSS 5.4
Knowage Suite 7.3 - Unauthenticated Reflected Cross-Site Scripting via AdapterHTTP TargetService Parameter
CVSS 6.1
Knowage Suite 7.3 - Stored Client-Side Template Injection via Name Parameter
CVSS 5.4
Syracom Secure Login < 3.1.1.0 - Open Redirect via PIN Validation Target Parameter
CVSS 6.1
LTB Self Service Password <1.5.4 - RCE
CVSS 9.8
AChecker 1.5 - Unauthenticated Path Traversal via download.php path parameter
CVSS 7.5
Bambu Studio <= 2.1.1.52 - Unauthenticated Remote Code Execution via Network Plugin Loading
CVSS 6.1