Steve Ikeoka
18 exploits
Active since Feb 2023
GeoServer < 2.18.7 and 2.18.7-2.21.4 - SQL Injection via OGC Filter and CQL Expressions
CVSS 9.8
GeoServer < 2.23.4, 2.24.1 - Authenticated Arbitrary File Upload and Remote Code Execution via REST Coverage Store API
CVSS 7.2
GeoServer < 2.23.4, 2.24.1 - Authenticated Arbitrary File Upload and Remote Code Execution via REST Coverage Store API
CVSS 7.2
GeoServer < 2.23.5 and 2.24.2 - Authenticated Arbitrary File Renaming via REST Coverage Store or Data Store API
CVSS 6.0
GeoServer < 2.23.4 and 2.24.1 - Authenticated Stored Cross-Site Scripting via WMS GetMap SVG Output Format
CVSS 4.8
GeoServer < 2.23.3 and 2.24.1 - Authenticated Stored Cross-Site Scripting via WMS GetMap OpenLayers Output Format
CVSS 4.8
GeoServer < 2.23.4 and 2.24.1 - Authenticated Stored Cross-Site Scripting in MapML HTML Page
CVSS 4.8
GeoTools < 24.7 and 28.0-28.2 - SQL Injection via OGC Filter Execution
CVSS 9.8
GeoServer < 2.23.3 - Authenticated Stored Cross-Site Scripting via Style/Legend Resource Upload
CVSS 4.8
GeoServer < 2.23.5 and 2.24.2 - Authenticated Arbitrary File Renaming via REST Coverage Store or Data Store API
CVSS 6.0
GeoServer < 2.23.4 and 2.24.1 - Authenticated Stored Cross-Site Scripting via WMS GetMap SVG Output Format
CVSS 4.8
GeoServer < 2.23.2 - Authenticated Stored Cross-Site Scripting in GWC Seed Form
CVSS 4.8
GeoServer < 2.23.3 and 2.24.1 - Authenticated Stored Cross-Site Scripting via WMS GetMap OpenLayers Output Format
CVSS 4.8
GeoServer < 2.23.4 and 2.24.1 - Authenticated Stored Cross-Site Scripting in MapML HTML Page
CVSS 4.8
GeoServer <2.23.5-2.24.3 - Info Disclosure
CVSS 7.5
GeoTools < 29.6, 30.0-30.4, 31.0-31.2 - Remote Code Execution via XPath Expression Evaluation
CVSS 9.8
GeoServer < 2.25.0 - Reflected Cross-Site Scripting via WMS GetFeatureInfo SLD_BODY Parameter
CVSS 6.1
Geoserver unauthenticated Remote Code Execution
CVSS 9.8