r1bbit
20 exploits
Active since Jan 2025
JFinalOA < 2025.01.01 - Cross-Site Scripting via /apply/getEditPage?view Interface
CVSS 4.6
JFinalOA < 2025-01-01 - SQL Injection via getWorkFlowHis insid Parameter
CVSS 8.8
JFinalOA < 2025.01.01 - Cross-Site Scripting via getBusinessUploadListPage Interface
CVSS 4.8
JFinalOA < 2025.01.01 - Cross-Site Scripting via openSelectManyUserPage Interface
CVSS 4.8
JFinalOA < 2025.01.01 - Cross-Site Scripting via /bumph/getDraftListPage
CVSS 4.8
JFinalOA < 2025.01.01 - Cross-Site Scripting via common/getEditPage?view Interface
CVSS 4.8
JFinalOA < 2025-01-01 - SQL Injection via oaContractApply.id Parameter
CVSS 8.8
JFinalOA < 2025-01-01 - SQL Injection via borrowmoney/listData applyUser Parameter
CVSS 8.8
JFinalOA < 2025-01-01 - SQL Injection via validRoleKey Parameter
CVSS 9.8
yimioa < 2024-07-04 - SQL Injection in UserMapper.xml listNameBySql Function
CVSS 6.3
yimioa < 2024.07.04 - SQL Injection via AddressDao.xml Mapper
CVSS 6.1
yimioa < 2024-07-04 - SQL Injection via OaNoticeMapper.xml sort Argument
CVSS 6.3
yimioa < v2024.07.04 - XML External Entity Injection in XMLParse.java
CVSS 8.1
yimioa < 2024-07-04 - Information Disclosure via /resources/application.yml
CVSS 4.2
yimioa < 2024.07.04 - Unauthenticated Administrator Password Modification via WebSecurityConfig
CVSS 7.3
yimioa < 2024-07-04 - SQL Injection via OaNoticeMapper.xml selectNoticeList()
CVSS 6.1
yimioa < 2024.07.04 - SQL Injection via listNameBySql() Method
CVSS 6.1
yimioa < 2024-07-04 - SQL Injection in AddressDao.xml selectList Function
CVSS 6.3
yimioa < 2024-07-04 - Improper Authorization in /oa/setup/setup.jsp
CVSS 5.3
ywoa <2024.07.03 - XML External Entity Reference
CVSS 6.3