185.194.90.11

Regular View Raw Data
Last Seen: 2024-05-10
Tags:
starttls

GeneralInformation

Hostnames 1-2-1mentors.com
daisydaisydaisy.com
ifyoulikeflowers.com
www.admin.ifyoulikeflowers.com
www.lindajeanjohn.ifyoulikeflowers.com
www.lindajohn.ifyoulikeflowers.com
beerus-lon.krystal.uk
lindajeanjohn.com
lindajohn.co.uk
Domains 1-2-1mentors.com daisydaisydaisy.com ifyoulikeflowers.com krystal.uk lindajeanjohn.com lindajohn.co.uk 
Country United Kingdom
City London
Organization Krystal Hosting Ltd
ISP Krystal Hosting Ltd
ASN AS12488

Vulnerabilities

Note: the device may not be impacted by all of these issues. The vulnerabilities are implied based on the software and version.

CVE-2024-3097 The WordPress Gallery Plugin – NextGEN Gallery plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the get_item function in versions up to, and including, 3.59. This makes it possible for unauthenticated attackers to extract sensitive data including EXIF and other metadata of any image uploaded through the plugin.
CVE-2023-48328 Cross-Site Request Forgery (CSRF) vulnerability in Imagely WordPress Gallery Plugin – NextGEN Gallery allows Cross Site Request Forgery.This issue affects WordPress Gallery Plugin – NextGEN Gallery: from n/a through 3.37.
CVE-2023-3279 The WordPress Gallery Plugin WordPress plugin before 3.39 does not validate some block attributes before using them to generate paths passed to include function/s, allowing Admin users to perform LFI attacks
CVE-2023-3155 The WordPress Gallery Plugin WordPress plugin before 3.39 is vulnerable to Arbitrary File Read and Delete due to a lack of input parameter validation in the `gallery_edit` function, allowing an attacker to access arbitrary resources on the server.
CVE-2023-3154 The WordPress Gallery Plugin WordPress plugin before 3.39 is vulnerable to PHAR Deserialization due to a lack of input parameter validation in the `gallery_edit` function, allowing an attacker to access arbitrary resources on the server.
CVE-2022-38468 Cross-Site Request Forgery (CSRF) vulnerability in Imagely WordPress Gallery Plugin – NextGEN Gallery plugin <= 3.28 leading to thumbnail alteration.
CVE-2020-35943 4.3A Cross-Site Request Forgery (CSRF) issue in the NextGEN Gallery plugin before 3.5.0 for WordPress allows File Upload. (It is possible to bypass CSRF protection by simply not including a nonce parameter.)
CVE-2020-35942 6.8A Cross-Site Request Forgery (CSRF) issue in the NextGEN Gallery plugin before 3.5.0 for WordPress allows File Upload and Local File Inclusion via settings modification, leading to Remote Code Execution and XSS. (It is possible to bypass CSRF protection by simply not including a nonce parameter.)
CVE-2019-14314 7.5A SQL injection vulnerability exists in the Imagely NextGEN Gallery plugin before 3.2.11 for WordPress. Successful exploitation of this vulnerability would allow a remote attacker to execute arbitrary SQL commands on the affected system via modules/nextgen_gallery_display/package.module.nextgen_gallery_display.php.
-2103850531 | 2024-05-09T07:52:02.552101
  
80 / tcp
1098206132 | 2024-05-09T00:13:33.908622
  
110 / tcp
-1568038836 | 2024-05-10T15:25:59.415754
  
443 / tcp
1448276401 | 2024-05-10T03:11:26.740200
  
2080 / tcp
-279894474 | 2024-04-24T10:35:52.336713
  
2082 / tcp
923187462 | 2024-04-12T09:26:44.422497
  
2083 / tcp
1096897172 | 2024-04-26T23:45:11.004874
  
2095 / tcp



Contact Us

Shodan ® - All rights reserved