138.197.229.35

Regular View Raw Data
Last Seen: 2024-05-02

GeneralInformation

Hostnames hosting.avallo.net
autoconfig.hosting.avallo.net
autodiscover.hosting.avallo.net
cpanel.hosting.avallo.net
cpcalendars.hosting.avallo.net
cpcontacts.hosting.avallo.net
ipv6.hosting.avallo.net
mail.hosting.avallo.net
webdisk.hosting.avallo.net
webmail.hosting.avallo.net
whm.hosting.avallo.net
www.hosting.avallo.net
leftruck.com
www.leftruck.com
Domains avallo.net leftruck.com 
Cloud Provider DigitalOcean
Cloud Region us-nj
Country United States
City North Bergen
Organization DigitalOcean, LLC
ISP DigitalOcean, LLC
ASN AS14061

WebTechnologies

Vulnerabilities

Note: the device may not be impacted by all of these issues. The vulnerabilities are implied based on the software and version.

CVE-2022-37454 The Keccak XKCP SHA-3 reference implementation before fdc6fef has an integer overflow and resultant buffer overflow that allows attackers to execute arbitrary code or eliminate expected cryptographic properties. This occurs in the sponge function interface.
CVE-2022-31629 In PHP versions before 7.4.31, 8.0.24 and 8.1.11, the vulnerability enables network and same-site attackers to set a standard insecure cookie in the victim's browser which is treated as a `__Host-` or `__Secure-` cookie by PHP applications.
CVE-2022-31628 In PHP versions before 7.4.31, 8.0.24 and 8.1.11, the phar uncompressor code would recursively uncompress "quines" gzip files, resulting in an infinite loop.
CVE-2017-8923 7.5The zend_string_extend function in Zend/zend_string.h in PHP through 7.1.5 does not prevent changes to string objects that result in a negative length, which allows remote attackers to cause a denial of service (application crash) or possibly have unspecified other impact by leveraging a script's use of .= with a long string.
CVE-2013-2220 7.5Buffer overflow in the radius_get_vendor_attr function in the Radius extension before 1.2.7 for PHP allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a large Vendor Specific Attributes (VSA) length value.
CVE-2007-3205 5.0The parse_str function in (1) PHP, (2) Hardened-PHP, and (3) Suhosin, when called without a second parameter, might allow remote attackers to overwrite arbitrary variables by specifying variable names and values in the string to be parsed. NOTE: it is not clear whether this is a design limitation of the function or a bug in PHP, although it is likely to be regarded as a bug in Hardened-PHP and Suhosin.
-861887828 | 2024-04-15T06:01:47.053371
  
21 / tcp
548193888 | 2024-04-28T17:22:19.591092
  
53 / tcp
548193888 | 2024-04-19T14:21:52.245098
  
53 / udp
-555543104 | 2024-04-28T16:04:00.247613
  
80 / tcp
1098206132 | 2024-04-20T23:28:41.406269
  
110 / tcp
1315965377 | 2024-04-23T03:28:14.078152
  
143 / tcp
2035851904 | 2024-05-02T17:09:45.844337
  
443 / tcp
-900832910 | 2024-04-19T01:36:57.402733
  
465 / tcp
879818472 | 2024-04-17T14:55:14.364555
  
587 / tcp
-1132241830 | 2024-04-14T07:36:49.612721
  
993 / tcp
-1001764030 | 2024-04-28T23:50:11.384003
  
995 / tcp
1914620401 | 2024-04-26T19:56:09.877178
  
2082 / tcp
-33879452 | 2024-05-01T09:41:17.399242
  
2083 / tcp
-1637484950 | 2024-04-10T17:25:18.904087
  
2086 / tcp
421373246 | 2024-04-28T00:13:47.414604
  
2087 / tcp



Contact Us

Shodan ® - All rights reserved