74.208.84.105

Regular View Raw Data
Last Seen: 2024-05-20

GeneralInformation

Hostnames dragonnet.work
planroom.justsmartguys.com
planroom.mbce.com
Domains dragonnet.work justsmartguys.com mbce.com 
Country United States
City Kansas City
Organization IONOS Inc.
ISP IONOS SE
ASN AS8560

WebTechnologies

JavaScript frameworks
JavaScript libraries

Vulnerabilities

Note: the device may not be impacted by all of these issues. The vulnerabilities are implied based on the software and version.

CVE-2020-7656 4.3jquery prior to 1.9.0 allows Cross-site Scripting attacks via the load method. The load method fails to recognize and remove "<script>" HTML tags that contain a whitespace character, i.e: "</script >", which results in the enclosed script logic to be executed.
CVE-2020-11023 4.3In jQuery versions greater than or equal to 1.0.3 and before 3.5.0, passing HTML containing <option> elements from untrusted sources - even after sanitizing it - to one of jQuery's DOM manipulation methods (i.e. .html(), .append(), and others) may execute untrusted code. This problem is patched in jQuery 3.5.0.
CVE-2020-11022 4.3In jQuery versions greater than or equal to 1.2 and before 3.5.0, passing HTML from untrusted sources - even after sanitizing it - to one of jQuery's DOM manipulation methods (i.e. .html(), .append(), and others) may execute untrusted code. This problem is patched in jQuery 3.5.0.
CVE-2019-11358 4.3jQuery before 3.4.0, as used in Drupal, Backdrop CMS, and other products, mishandles jQuery.extend(true, {}, ...) because of Object.prototype pollution. If an unsanitized source object contained an enumerable __proto__ property, it could extend the native Object.prototype.
CVE-2015-9251 4.3jQuery before 3.0.0 is vulnerable to Cross-site Scripting (XSS) attacks when a cross-domain Ajax request is performed without the dataType option, causing text/javascript responses to be executed.
CVE-2013-2220 7.5Buffer overflow in the radius_get_vendor_attr function in the Radius extension before 1.2.7 for PHP allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a large Vendor Specific Attributes (VSA) length value.
CVE-2012-6708 4.3jQuery before 1.9.0 is vulnerable to Cross-site Scripting (XSS) attacks. The jQuery(strInput) function does not differentiate selectors from HTML in a reliable fashion. In vulnerable versions, jQuery determined whether the input was HTML by looking for the '<' character anywhere in the string, giving attackers more flexibility when attempting to construct a malicious payload. In fixed versions, jQuery only deems the input to be HTML if it explicitly starts with the '<' character, limiting exploitability only to attackers who can control the beginning of a string, which is far less common.
CVE-2007-3205 5.0The parse_str function in (1) PHP, (2) Hardened-PHP, and (3) Suhosin, when called without a second parameter, might allow remote attackers to overwrite arbitrary variables by specifying variable names and values in the string to be parsed. NOTE: it is not clear whether this is a design limitation of the function or a bug in PHP, although it is likely to be regarded as a bug in Hardened-PHP and Suhosin.
-467645697 | 2024-05-18T19:09:38.043551
  
21 / tcp
-1413943816 | 2024-05-14T21:35:14.538350
  
22 / tcp
-1104017998 | 2024-05-09T05:39:18.206562
  
25 / tcp
-2144976289 | 2024-05-02T17:06:42.835712
  
80 / tcp
32350811 | 2024-05-19T20:54:11.046895
  
110 / tcp
-127552878 | 2024-05-13T14:53:33.513868
  
143 / tcp
59626144 | 2024-05-20T15:24:00.774579
  
443 / tcp
-1026691115 | 2024-05-17T12:16:59.284285
  
465 / tcp
-977792535 | 2024-05-15T20:09:44.623709
  
587 / tcp
-628402902 | 2024-05-14T21:06:03.580091
  
993 / tcp
137762461 | 2024-05-15T03:51:33.112533
  
995 / tcp
969606016 | 2024-05-15T11:10:43.528337
  
8443 / tcp



Contact Us

Shodan ® - All rights reserved