andikahilmy
165 exploits
Active since Aug 2013
Apache Sling XSS Protection API 1.0.4-1.0.18 and 2.0.0 - Cross-Site Scripting via URL Validation Bypass
CVSS 6.1
Swagger-Parser <=1.0.30 & Swagger Codegen <=2.2.2 - RCE
CVSS 8.8
JBoss RESTEasy < 3.1.2 - Remote Code Execution via YamlProvider Unmarshalling
CVSS 8.1
Red Hat JBoss WildFly Application Server < 10.1.0 - Denial of Service via HTTP Header Cache Exhaustion
CVSS 7.5
Spark < 2.5 - Path Traversal via URI
CVSS 7.5
Apache Brooklyn <0.10.0 - Code Injection
CVSS 8.8
Apache Qpid Broker for Java <6.0.6, <6.1.1 - Info Disclosure
CVSS 7.5
jackson-dataformat-xml < 2.7.8 - Server-Side Request Forgery via DTD Processing
CVSS 8.6
Apache Tika < 1.14 - Remote Code Execution via MATLAB File Deserialization
CVSS 9.8
Apache Shiro < 1.3.2 - Filter Bypass via Non-Root Servlet Context Path
CVSS 7.5
Apache Jackrabbit < 2.4.6 - CSRF
CVSS 8.8
Apache Qpid AMQP JMS Client < 6.0.4 & JMS (AMQP 1.0) < 0.10.0 - RCE via JMS ObjectMessage Deserialization
CVSS 7.5
Apache CXF Fediz 1.2.0-1.2.2 and 1.3.0 - Improper Access Control via SAML AudienceRestriction Bypass
CVSS 9.8
Apache Tomcat 7.x < 7.0.70, 8.x < 8.0.36, 8.5.x < 8.5.3, 9.x < 9.0.0.M7 - Denial of Service via Long Boundary String
CVSS 7.5
Apache Commons FileUpload <1.3.3 - RCE
CVSS 9.8
jsoup < 1.8.3 - Cross-Site Scripting
CVSS 6.1
PicketLink <2.7.0 - Info Disclosure
jackson-databind <2.8.10, 2.9.1 - Code Injection
CVSS 9.8
async-http-client < 2.0.35 - Server-Side Request Forgery via Fragment Identifier
CVSS 7.5
libpam4j <= 1.8 - Authentication Bypass via Disabled Account Validation
CVSS 6.5
Undertow <1.4.17, <1.3.31, <2.0.0 - HTTP Request Smuggling
CVSS 2.6
Plexus-utils <3.0.16 - Command Injection
CVSS 9.8
nv-websocket-client - Man-in-the-Middle
CVSS 5.9
Swagger-Parser <= 1.0.30 and Swagger-Codegen <= 2.2.2 - Remote Code Execution via YAML Parsing
CVSS 8.8
Apache MyFaces Core <2.0.12, <2.1.6 - Path Traversal