taojinlong
19 exploits
Active since Oct 2022
Dataease < 1.18.15 - Deserialization of Untrusted Data in MySQL Datasource
CVSS 9.1
DataEase is Vulnerable to H2 JDBC RCE Bypass
CVSS 8.1
Dataease < 1.15.2 - Remote Code Execution via Mysql JDBC Deserialization
CVSS 9.8
Dataease < 1.18.15 - Deserialization of Untrusted Data in MySQL Datasource
CVSS 9.1
DataEase < 1.18.25 - Remote Code Execution via PostgreSQL JDBC Deserialization
CVSS 9.8
DataEase < 1.18.27 - Authenticated Remote Code Execution via JDBC Connection String Injection
CVSS 8.8
DataEase < 1.18.27 - Authenticated SQL Injection via JDBC Connection String
CVSS 8.1
DataEase < 2.10.10 - Improper Access Control via JDBC Statement Manipulation
CVSS 8.8
DataEase < 2.10.12 - Remote Code Execution via H2 JDBC URL Bypass
CVSS 9.8
DataEase < 2.10.12 - Deserialization of Untrusted Data via JNDI Injection
CVSS 9.8
Dataease < 2.10.13 - Server-Side Request Forgery via DB2 JDBC LDAP Parameter
CVSS 9.8
Dataease <= 2.10.12 - Remote Code Execution via Impala JDBC Connection String JNDI Injection
CVSS 9.8
Dataease < 2.10.13 - Remote Code Execution via H2 JDBC URL Deserialization
CVSS 9.8
DataEase < 2.10.14 - JDBC URL Injection via DB2 and MongoDB Data Source Configuration
CVSS 7.5
DataEase < 2.10.14 - Authenticated Remote Code Execution via H2 JDBC Driver Bypass
CVSS 8.8
DataEase < 2.10.14 - SQL Injection via tableName Parameter
CVSS 8.8
dataease < 2.10.15 - Server-Side Request Forgery via DNS Protocol
CVSS 9.8
Dataease < 2.10.15 - JNDI Injection via JDBC Connection
CVSS 9.8
Dataease < 2.10.17 - JNDI Injection via iiop, corbaname, and iiopname Schemes
CVSS 9.8