209.59.129.52

Regular View Raw Data
Last Seen: 2024-06-05
Tags:
starttls

GeneralInformation

Hostnames offroaders.com
cpanel.offroaders.com
cpcalendars.offroaders.com
cpcontacts.offroaders.com
host.offroaders.com
autoconfig.host.offroaders.com
autodiscover.host.offroaders.com
ipv6.host.offroaders.com
mail.host.offroaders.com
www.host.offroaders.com
mail.offroaders.com
webdisk.offroaders.com
webmail.offroaders.com
www.offroaders.com
Domains offroaders.com 
Country United States
City Dimondale
Organization Liquid Web, L.L.C
ISP Liquid Web, L.L.C
ASN AS32244

WebTechnologies

Vulnerabilities

Note: the device may not be impacted by all of these issues. The vulnerabilities are implied based on the software and version.

CVE-2024-3097 The WordPress Gallery Plugin – NextGEN Gallery plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the get_item function in versions up to, and including, 3.59. This makes it possible for unauthenticated attackers to extract sensitive data including EXIF and other metadata of any image uploaded through the plugin.
CVE-2023-48328 Cross-Site Request Forgery (CSRF) vulnerability in Imagely WordPress Gallery Plugin – NextGEN Gallery allows Cross Site Request Forgery.This issue affects WordPress Gallery Plugin – NextGEN Gallery: from n/a through 3.37.
CVE-2023-3279 The WordPress Gallery Plugin WordPress plugin before 3.39 does not validate some block attributes before using them to generate paths passed to include function/s, allowing Admin users to perform LFI attacks
CVE-2023-3155 The WordPress Gallery Plugin WordPress plugin before 3.39 is vulnerable to Arbitrary File Read and Delete due to a lack of input parameter validation in the `gallery_edit` function, allowing an attacker to access arbitrary resources on the server.
CVE-2023-3154 The WordPress Gallery Plugin WordPress plugin before 3.39 is vulnerable to PHAR Deserialization due to a lack of input parameter validation in the `gallery_edit` function, allowing an attacker to access arbitrary resources on the server.
CVE-2022-38468 Cross-Site Request Forgery (CSRF) vulnerability in Imagely WordPress Gallery Plugin – NextGEN Gallery plugin <= 3.28 leading to thumbnail alteration.
CVE-2020-35943 4.3A Cross-Site Request Forgery (CSRF) issue in the NextGEN Gallery plugin before 3.5.0 for WordPress allows File Upload. (It is possible to bypass CSRF protection by simply not including a nonce parameter.)
CVE-2020-35942 6.8A Cross-Site Request Forgery (CSRF) issue in the NextGEN Gallery plugin before 3.5.0 for WordPress allows File Upload and Local File Inclusion via settings modification, leading to Remote Code Execution and XSS. (It is possible to bypass CSRF protection by simply not including a nonce parameter.)
249092759 | 2024-06-05T03:50:52.904145
  
21 / tcp
-513897352 | 2024-06-03T09:25:16.443789
  
53 / tcp
139693874 | 2024-05-25T15:38:02.515127
  
80 / tcp
1952082069 | 2024-06-04T21:39:28.210641
  
110 / tcp
-2049848973 | 2024-06-05T06:05:41.019155
  
443 / tcp
1424834077 | 2024-05-12T21:17:13.775239
  
465 / tcp
-1001764030 | 2024-05-25T23:45:52.887624
  
995 / tcp
-1603406084 | 2024-06-05T06:05:32.205886
  
2082 / tcp
-2138538156 | 2024-06-05T06:05:35.368646
  
2083 / tcp



Contact Us

Shodan ® - All rights reserved