{ "host": "prometheus.lan.ddnsgeek.com", "generated_at": "2026-04-07T03:49:38.723646+00:00", "required_reproduction_step_before_ticket": "Before creating a ticket, reproduce vulnerable behavior directly (e.g., crafted request causing data exposure, traversal read, or exploitable crash) and attach request/response proof. Banner or script signature matches alone are insufficient.", "findings": [ { "host": "prometheus.lan.ddnsgeek.com", "cve": "CVE-2009-3733", "affected_host": "prometheus.lan.ddnsgeek.com", "endpoint": "/sdk/%2E%2E/%2E%2E/%2E%2E/%2E%2E/%2E%2E/%2E%2E/%2E%2E/etc/vmware/hostd/vmInventory.xml", "product_version_evidence": [ "No explicit product/version fingerprint in nmap service line." ], "exploit_precondition": "Target must expose VMware SDK endpoint (/sdk) and allow traversal into host files.", "reproducibility": "not-reproduced", "disposition": "not-applicable", "disposition_rationale": "Only unauthorized responses were observed; vulnerable behavior was not reproduced and signature is likely a false positive.", "required_reproduction_step_before_ticket": "Before creating a ticket, reproduce vulnerable behavior directly (e.g., crafted request causing data exposure, traversal read, or exploitable crash) and attach request/response proof. Banner or script signature matches alone are insufficient.", "evidence_sources": [ { "file": "results/prometheus.lan.ddnsgeek.com/scans/_patterns.log", "match_count": 2 }, { "file": "results/prometheus.lan.ddnsgeek.com/scans/tcp443/tcp_443_https_nmap.txt", "endpoint": "/sdk/../../../../../../../etc/vmware/hostd/vmInventory.xml", "evidence": "Possible path traversal in VMWare (CVE-2009-3733) (401 Unauthorized)" }, { "file": "results/prometheus.lan.ddnsgeek.com/scans/tcp443/tcp_443_https_nmap.txt", "endpoint": "/sdk/%2E%2E/%2E%2E/%2E%2E/%2E%2E/%2E%2E/%2E%2E/%2E%2E/etc/vmware/hostd/vmInventory.xml", "evidence": "Possible path traversal in VMWare (CVE-2009-3733) (401 Unauthorized)" } ] }, { "host": "prometheus.lan.ddnsgeek.com", "cve": "CVE-2011-0966", "affected_host": "prometheus.lan.ddnsgeek.com", "endpoint": "/cwhp/auditLog.do?file=..\\..\\..\\..\\..\\..\\..\\Program%20Files\\CSCOpx\\MDC\\Tomcat\\webapps\\triveni\\WEB-INF\\classes\\schedule.properties", "product_version_evidence": [ "No explicit product/version fingerprint in nmap service line." ], "exploit_precondition": "Target must be Cisco Unified Operations Manager 8.0/8.5 with vulnerable auditLog.do traversal handling.", "reproducibility": "not-reproduced", "disposition": "not-applicable", "disposition_rationale": "Only unauthorized responses were observed; vulnerable behavior was not reproduced and signature is likely a false positive.", "required_reproduction_step_before_ticket": "Before creating a ticket, reproduce vulnerable behavior directly (e.g., crafted request causing data exposure, traversal read, or exploitable crash) and attach request/response proof. Banner or script signature matches alone are insufficient.", "evidence_sources": [ { "file": "results/prometheus.lan.ddnsgeek.com/scans/_patterns.log", "match_count": 4 }, { "file": "results/prometheus.lan.ddnsgeek.com/scans/tcp443/tcp_443_https_nmap.txt", "endpoint": "/cwhp/auditLog.do?file=..\\..\\..\\..\\..\\..\\..\\boot.ini", "evidence": "Possible CiscoWorks (CuOM 8.0 and 8.5) Directory traversal (CVE-2011-0966) (Windows) (401 Unauthorized)" }, { "file": "results/prometheus.lan.ddnsgeek.com/scans/tcp443/tcp_443_https_nmap.txt", "endpoint": "/cwhp/auditLog.do?file=..\\..\\..\\..\\..\\..\\..\\Program%20Files\\CSCOpx\\MDC\\Tomcat\\webapps\\triveni\\WEB-INF\\classes\\schedule.properties", "evidence": "Possible CiscoWorks (CuOM 8.0 and 8.5) Directory traversal (CVE-2011-0966) (Windows) (401 Unauthorized)" }, { "file": "results/prometheus.lan.ddnsgeek.com/scans/tcp443/tcp_443_https_nmap.txt", "endpoint": "/cwhp/auditLog.do?file=..\\..\\..\\..\\..\\..\\..\\Program%20Files\\CSCOpx\\lib\\classpath\\com\\cisco\\nm\\cmf\\dbservice2\\DBServer.properties", "evidence": "Possible CiscoWorks (CuOM 8.0 and 8.5) Directory traversal (CVE-2011-0966) (Windows) (401 Unauthorized)" }, { "file": "results/prometheus.lan.ddnsgeek.com/scans/tcp443/tcp_443_https_nmap.txt", "endpoint": "/cwhp/auditLog.do?file=..\\..\\..\\..\\..\\..\\..\\Program%20Files\\CSCOpx\\log\\dbpwdChange.log", "evidence": "Possible CiscoWorks (CuOM 8.0 and 8.5) Directory traversal (CVE-2011-0966) (Windows) (401 Unauthorized)" } ] }, { "host": "prometheus.lan.ddnsgeek.com", "cve": "CVE-2018-10822", "affected_host": "prometheus.lan.ddnsgeek.com", "endpoint": "/uir//etc/passwd", "product_version_evidence": [ "No explicit product/version fingerprint in nmap service line." ], "exploit_precondition": "Target must be affected D-Link router firmware exposing /uir/ traversal path.", "reproducibility": "not-reproduced", "disposition": "not-applicable", "disposition_rationale": "Only unauthorized responses were observed; vulnerable behavior was not reproduced and signature is likely a false positive.", "required_reproduction_step_before_ticket": "Before creating a ticket, reproduce vulnerable behavior directly (e.g., crafted request causing data exposure, traversal read, or exploitable crash) and attach request/response proof. Banner or script signature matches alone are insufficient.", "evidence_sources": [ { "file": "results/prometheus.lan.ddnsgeek.com/scans/_patterns.log", "match_count": 1 }, { "file": "results/prometheus.lan.ddnsgeek.com/scans/tcp443/tcp_443_https_nmap.txt", "endpoint": "/uir//etc/passwd", "evidence": "Possible D-Link router directory traversal vulnerability (CVE-2018-10822) (401 Unauthorized)" } ] }, { "host": "prometheus.lan.ddnsgeek.com", "cve": "CVE-2018-10824", "affected_host": "prometheus.lan.ddnsgeek.com", "endpoint": "/uir//tmp/csman/0", "product_version_evidence": [ "No explicit product/version fingerprint in nmap service line." ], "exploit_precondition": "Target must be affected D-Link router firmware exposing plaintext credential path under /tmp/csman.", "reproducibility": "not-reproduced", "disposition": "not-applicable", "disposition_rationale": "Only unauthorized responses were observed; vulnerable behavior was not reproduced and signature is likely a false positive.", "required_reproduction_step_before_ticket": "Before creating a ticket, reproduce vulnerable behavior directly (e.g., crafted request causing data exposure, traversal read, or exploitable crash) and attach request/response proof. Banner or script signature matches alone are insufficient.", "evidence_sources": [ { "file": "results/prometheus.lan.ddnsgeek.com/scans/_patterns.log", "match_count": 1 }, { "file": "results/prometheus.lan.ddnsgeek.com/scans/tcp443/tcp_443_https_nmap.txt", "endpoint": "/uir//tmp/csman/0", "evidence": "Possible D-Link router plaintext password file exposure (CVE-2018-10824) (401 Unauthorized)" } ] } ] }