185.246.65.20

Regular View Raw Data
Last Seen: 2024-05-17
Tags:
eol-product

GeneralInformation

Hostnames yuriy1.lukaschuk.fvds.ru
finance.praktika.fit
kom.praktika.fit
mailing.praktika.fit
mol.praktika.fit
report.praktika.fit
sin.praktika.fit
teh.praktika.fit
worldfitnes.online
worldfitnes.ru
www.worldfitnes.ru
Domains fvds.ru praktika.fit worldfitnes.online worldfitnes.ru 
Country Russian Federation
City Moscow
Organization JSC Datacenter
ISP JSC IOT
ASN AS29182
Operating System Ubuntu

WebTechnologies

Database managers
Databases
JavaScript libraries
Programming languages
UI frameworks

Vulnerabilities

Note: the device may not be impacted by all of these issues. The vulnerabilities are implied based on the software and version.

CVE-2023-44487 The HTTP/2 protocol allows a denial of service (server resource consumption) because request cancellation can reset many streams quickly, as exploited in the wild in August through October 2023.
CVE-2023-25727 In phpMyAdmin before 4.9.11 and 5.x before 5.2.1, an authenticated user can trigger XSS by uploading a crafted .sql file through the drag-and-drop interface.
CVE-2022-23808 4.3An issue was discovered in phpMyAdmin 5.1 before 5.1.2. An attacker can inject malicious code into aspects of the setup script, which can allow XSS or HTML injection.
CVE-2022-23807 4.0An issue was discovered in phpMyAdmin 4.9 before 4.9.8 and 5.1 before 5.1.2. A valid user who is already authenticated to phpMyAdmin can manipulate their account to bypass two-factor authentication for future login instances.
CVE-2022-0813 5.0PhpMyAdmin 5.1.1 and before allows an attacker to retrieve potentially sensitive information by creating invalid requests. This affects the lang parameter, the pma_parameter, and the cookie section.
CVE-2021-3618 5.8ALPACA is an application layer protocol content confusion attack, exploiting TLS servers implementing different protocols but using compatible certificates, such as multi-domain or wildcard certificates. A MiTM attacker having access to victim's traffic at the TCP/IP layer can redirect traffic from one subdomain to another, resulting in a valid TLS session. This breaks the authentication of TLS and cross-protocol attacks may be possible where the behavior of one protocol service may compromise the other at the application layer.
CVE-2021-23017 6.8A security issue in nginx resolver was identified, which might allow an attacker who is able to forge UDP packets from the DNS server to cause 1-byte memory overwrite, resulting in worker process crash or potential other impact.
CVE-2020-22452 SQL Injection vulnerability in function getTableCreationQuery in CreateAddField.php in phpMyAdmin 5.x before 5.2.0 via the tbl_storage_engine or tbl_collation parameters to tbl_create.php.

OpenPorts

-1062991961 | 2024-05-16T19:03:12.672157
  
21 / tcp
-394987840 | 2024-05-17T11:43:02.681060
  
80 / tcp
-277813891 | 2024-05-08T06:11:06.866491
  
225 / tcp
-554746519 | 2024-05-16T09:28:45.504916
  
443 / tcp



Contact Us

Shodan ® - All rights reserved