84.16.241.139

Regular View Raw Data
Last Seen: 2024-05-05

GeneralInformation

Hostnames server.const-tech.biz
Domains const-tech.biz 
Country Germany
City Reinheim
Organization Spitzenserver.de
ISP Leaseweb Deutschland GmbH
ASN AS28753

WebTechnologies

JavaScript libraries
Message boards
Programming languages

Vulnerabilities

Note: the device may not be impacted by all of these issues. The vulnerabilities are implied based on the software and version.

CVE-2023-39777 A cross-site scripting (XSS) vulnerability in the Admin Control Panel of vBulletin 5.7.5 and 6.0.0 allows attackers to execute arbitrary web scripts or HTML via the /login.php?do=login url parameter.
CVE-2019-17271 4.0vBulletin 5.5.4 allows SQL Injection via the ajax/api/hook/getHookList or ajax/api/widget/getWidgetList where parameter.
CVE-2019-17132 6.8vBulletin through 5.5.4 mishandles custom avatars.
CVE-2019-17131 4.3vBulletin before 5.5.4 allows clickjacking.
CVE-2019-17130 6.4vBulletin through 5.5.4 mishandles external URLs within the /core/vb/vurl.php file and the /core/vb/vurl directories.
CVE-2018-6200 5.8vBulletin 3.x.x and 4.2.x through 4.2.5 has an open redirect via the redirector.php url parameter.
CVE-2017-7569 5.0In vBulletin before 5.3.0, remote attackers can bypass the CVE-2016-6483 patch and conduct SSRF attacks by leveraging the behavior of the PHP parse_url function, aka VBV-17037.
CVE-2016-6483 5.0The media-file upload feature in vBulletin before 3.8.7 Patch Level 6, 3.8.8 before Patch Level 2, 3.8.9 before Patch Level 1, 4.x before 4.2.2 Patch Level 6, 4.2.3 before Patch Level 2, 5.x before 5.2.0 Patch Level 3, 5.2.1 before Patch Level 1, and 5.2.2 before Patch Level 1 allows remote attackers to conduct SSRF attacks via a crafted URL that results in a Redirection HTTP status code.
CVE-2014-9469 4.3Cross-site scripting (XSS) vulnerability in vBulletin 3.5.4, 3.6.0, 3.6.7, 3.8.7, 4.2.2, 5.0.5, and 5.1.3.
CVE-2014-9463 9.0functions_vbseo_hook.php in the VBSEO module for vBulletin allows remote authenticated users to execute arbitrary code via the HTTP Referer header to visitormessage.php.
CVE-2014-2022 7.1SQL injection vulnerability in includes/api/4/breadcrumbs_create.php in vBulletin 4.2.2, 4.2.1, 4.2.0 PL2, and earlier allows remote authenticated users to execute arbitrary SQL commands via the conceptid argument in an xmlrpc API request.
CVE-2014-2021 3.5Cross-site scripting (XSS) vulnerability in admincp/apilog.php in vBulletin 4.2.2 and earlier, and 5.0.x through 5.0.5 allows remote authenticated users to inject arbitrary web script or HTML via a crafted XMLRPC API request, as demonstrated using the client name.
CVE-2011-5251 5.8Open redirect vulnerability in forum/login.php in vBulletin 4.1.3 and earlier allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via the url parameter in a lostpw action.
CVE-2010-1077 6.8Directory traversal vulnerability in vbseo.php in Crawlability vBSEO plugin 3.1.0 for vBulletin allows remote attackers to include and execute arbitrary local files via directory traversal sequences in the vbseourl parameter.
-105847754 | 2024-04-29T19:04:14.944667
  
21 / tcp
1110485849 | 2024-04-21T01:16:35.028262
  
53 / tcp
1110485849 | 2024-05-05T23:16:07.473370
  
53 / udp
1976355766 | 2024-04-27T18:08:07.926594
  
80 / tcp
1952082069 | 2024-05-05T10:43:34.542062
  
110 / tcp
1559185454 | 2024-05-02T18:44:17.252766
  
143 / tcp
279030267 | 2024-05-05T03:01:33.979041
  
443 / tcp
206338616 | 2024-04-15T04:21:53.579416
  
465 / tcp
1008664291 | 2024-04-20T20:19:35.952859
  
587 / tcp
-1132241830 | 2024-05-05T13:13:44.970008
  
993 / tcp
-1001764030 | 2024-05-05T20:24:37.448519
  
995 / tcp
-1904105856 | 2024-04-27T05:59:09.528438
  
2077 / tcp
-827577623 | 2024-04-19T11:16:26.263427
  
2083 / tcp
-1014753683 | 2024-04-21T19:39:20.641231
  
2086 / tcp
-1781050573 | 2024-05-05T18:17:45.092686
  
2087 / tcp
-1555829215 | 2024-04-21T12:24:51.066493
  
2096 / tcp
-1017396243 | 2024-04-20T20:38:28.048123
  
3306 / tcp



Contact Us

Shodan ® - All rights reserved