shanika04

8 exploits Active since Aug 2016
CVE-2020-9483 NOMISEC HIGH STUB
Apache Skywalking < 6.6.0 - SQL Injection
**Resolved** When use H2/MySQL/TiDB as Apache SkyWalking storage, the metadata query through GraphQL protocol, there is a SQL injection vulnerability, which allows to access unpexcted data. Apache SkyWalking 6.0.0 to 6.6.0, 7.0.0 H2/MySQL/TiDB storage implementations don't use the appropriate way to set SQL parameters.
1 stars
CVSS 7.5
CVE-2020-1937 NOMISEC HIGH STUB
Apache Kylin < 2.3.2 - SQL Injection
Kylin has some restful apis which will concatenate SQLs with the user input string, a user is likely to be able to run malicious database queries.
CVSS 8.8
CVE-2019-5427 NOMISEC HIGH STUB
c3p0 <0.9.5.4 - Info Disclosure
c3p0 version < 0.9.5.4 may be exploited by a billion laughs attack when loading XML configuration due to missing protections against recursive entity expansion when loading configuration.
CVSS 7.5
CVE-2019-14900 NOMISEC MEDIUM STUB
Redhat Openstack < 5.3.18 - SQL Injection
A flaw was found in Hibernate ORM in versions before 5.3.18, 5.4.18 and 5.5.0.Beta1. A SQL injection in the implementation of the JPA Criteria API can permit unsanitized literals when a literal is used in the SELECT or GROUP BY parts of the query. This flaw could allow an attacker to access unauthorized information or possibly conduct further attacks.
CVSS 6.5
CVE-2019-5454 NOMISEC CRITICAL WRITEUP
Nextcloud - SQL Injection
SQL Injection in the Nextcloud Android app prior to version 3.0.0 allows to destroy a local cache when a harmful query is executed requiring to resetup the account.
CVSS 9.8
CVE-2018-20433 NOMISEC CRITICAL STUB
Mchange C3p0 < 0.9.5.3 - XXE
c3p0 0.9.5.2 allows XXE in extractXmlConfigFromInputStream in com/mchange/v2/c3p0/cfg/C3P0ConfigXmlUtils.java during initialization.
CVSS 9.8
CVE-2016-4999 NOMISEC CRITICAL STUB
Redhat Dashbuilder < 0.5.0 - SQL Injection
SQL injection vulnerability in the getStringParameterSQL method in main/java/org/dashbuilder/dataprovider/sql/dialect/DefaultDialect.java in Dashbuilder before 0.6.0.Beta1 allows remote attackers to execute arbitrary SQL commands via a data set lookup filter in the (1) Data Set Authoring or (2) Displayer editor UI.
CVSS 9.8
CVE-2016-4468 NOMISEC HIGH STUB
Cloudfoundry Cloud Foundry Uaa Bosh < 12.0 - SQL Injection
SQL injection vulnerability in Pivotal Cloud Foundry (PCF) before 238; UAA 2.x before 2.7.4.4, 3.x before 3.3.0.2, and 3.4.x before 3.4.1; UAA BOSH before 11.2 and 12.x before 12.2; Elastic Runtime before 1.6.29 and 1.7.x before 1.7.7; and Ops Manager 1.7.x before 1.7.8 allows remote authenticated users to execute arbitrary SQL commands via unspecified vectors.
CVSS 8.8