2414 lines
140 KiB
JSON
2414 lines
140 KiB
JSON
{
|
|
"host": "auth.lan.ddnsgeek.com",
|
|
"generated_at": "2026-04-14T07:48:16.890425+00:00",
|
|
"required_reproduction_step_before_ticket": "Before creating a ticket, reproduce vulnerable behavior directly (e.g., crafted request causing data exposure, traversal read, or exploitable crash) and attach request/response proof. Banner or script signature matches alone are insufficient.",
|
|
"findings": [
|
|
{
|
|
"host": "auth.lan.ddnsgeek.com",
|
|
"cve": "CVE-1999-0039",
|
|
"affected_host": "auth.lan.ddnsgeek.com",
|
|
"endpoint": "unknown",
|
|
"product_version_evidence": [
|
|
"http syn-ack ttl 55 Golang net/http server (Go-IPFS json-rpc or InfluxDB API)",
|
|
"http syn-ack ttl 55 Golang net/http server (Go-IPFS json-rpc or InfluxDB API)",
|
|
"http syn-ack ttl 55 Golang net/http server (Go-IPFS json-rpc or InfluxDB API)",
|
|
"ssl/http syn-ack ttl 55 Golang net/http server (Go-IPFS json-rpc or InfluxDB API)",
|
|
"ssl/http syn-ack ttl 55 Golang net/http server (Go-IPFS json-rpc or InfluxDB API)",
|
|
"tcpwrapped syn-ack ttl 56"
|
|
],
|
|
"exploit_precondition": "Validate affected product/version and exploit path prerequisites before filing.",
|
|
"reproducibility": "not-reproduced",
|
|
"disposition": "needs-manual-test",
|
|
"disposition_rationale": "Script/banner evidence exists, but no direct proof of exploit impact was captured in scan output.",
|
|
"required_reproduction_step_before_ticket": "Before creating a ticket, reproduce vulnerable behavior directly (e.g., crafted request causing data exposure, traversal read, or exploitable crash) and attach request/response proof. Banner or script signature matches alone are insufficient.",
|
|
"evidence_sources": [
|
|
{
|
|
"file": "results/auth.lan.ddnsgeek.com/scans/_patterns.log",
|
|
"match_count": 1
|
|
}
|
|
]
|
|
},
|
|
{
|
|
"host": "auth.lan.ddnsgeek.com",
|
|
"cve": "CVE-1999-0068",
|
|
"affected_host": "auth.lan.ddnsgeek.com",
|
|
"endpoint": "unknown",
|
|
"product_version_evidence": [
|
|
"http syn-ack ttl 55 Golang net/http server (Go-IPFS json-rpc or InfluxDB API)",
|
|
"http syn-ack ttl 55 Golang net/http server (Go-IPFS json-rpc or InfluxDB API)",
|
|
"http syn-ack ttl 55 Golang net/http server (Go-IPFS json-rpc or InfluxDB API)",
|
|
"ssl/http syn-ack ttl 55 Golang net/http server (Go-IPFS json-rpc or InfluxDB API)",
|
|
"ssl/http syn-ack ttl 55 Golang net/http server (Go-IPFS json-rpc or InfluxDB API)",
|
|
"tcpwrapped syn-ack ttl 56"
|
|
],
|
|
"exploit_precondition": "Validate affected product/version and exploit path prerequisites before filing.",
|
|
"reproducibility": "not-reproduced",
|
|
"disposition": "needs-manual-test",
|
|
"disposition_rationale": "Script/banner evidence exists, but no direct proof of exploit impact was captured in scan output.",
|
|
"required_reproduction_step_before_ticket": "Before creating a ticket, reproduce vulnerable behavior directly (e.g., crafted request causing data exposure, traversal read, or exploitable crash) and attach request/response proof. Banner or script signature matches alone are insufficient.",
|
|
"evidence_sources": [
|
|
{
|
|
"file": "results/auth.lan.ddnsgeek.com/scans/_patterns.log",
|
|
"match_count": 4
|
|
}
|
|
]
|
|
},
|
|
{
|
|
"host": "auth.lan.ddnsgeek.com",
|
|
"cve": "CVE-1999-0191",
|
|
"affected_host": "auth.lan.ddnsgeek.com",
|
|
"endpoint": "unknown",
|
|
"product_version_evidence": [
|
|
"http syn-ack ttl 55 Golang net/http server (Go-IPFS json-rpc or InfluxDB API)",
|
|
"http syn-ack ttl 55 Golang net/http server (Go-IPFS json-rpc or InfluxDB API)",
|
|
"http syn-ack ttl 55 Golang net/http server (Go-IPFS json-rpc or InfluxDB API)",
|
|
"ssl/http syn-ack ttl 55 Golang net/http server (Go-IPFS json-rpc or InfluxDB API)",
|
|
"ssl/http syn-ack ttl 55 Golang net/http server (Go-IPFS json-rpc or InfluxDB API)",
|
|
"tcpwrapped syn-ack ttl 56"
|
|
],
|
|
"exploit_precondition": "Validate affected product/version and exploit path prerequisites before filing.",
|
|
"reproducibility": "not-reproduced",
|
|
"disposition": "needs-manual-test",
|
|
"disposition_rationale": "Script/banner evidence exists, but no direct proof of exploit impact was captured in scan output.",
|
|
"required_reproduction_step_before_ticket": "Before creating a ticket, reproduce vulnerable behavior directly (e.g., crafted request causing data exposure, traversal read, or exploitable crash) and attach request/response proof. Banner or script signature matches alone are insufficient.",
|
|
"evidence_sources": [
|
|
{
|
|
"file": "results/auth.lan.ddnsgeek.com/scans/_patterns.log",
|
|
"match_count": 1
|
|
}
|
|
]
|
|
},
|
|
{
|
|
"host": "auth.lan.ddnsgeek.com",
|
|
"cve": "CVE-1999-0279",
|
|
"affected_host": "auth.lan.ddnsgeek.com",
|
|
"endpoint": "unknown",
|
|
"product_version_evidence": [
|
|
"http syn-ack ttl 55 Golang net/http server (Go-IPFS json-rpc or InfluxDB API)",
|
|
"http syn-ack ttl 55 Golang net/http server (Go-IPFS json-rpc or InfluxDB API)",
|
|
"http syn-ack ttl 55 Golang net/http server (Go-IPFS json-rpc or InfluxDB API)",
|
|
"ssl/http syn-ack ttl 55 Golang net/http server (Go-IPFS json-rpc or InfluxDB API)",
|
|
"ssl/http syn-ack ttl 55 Golang net/http server (Go-IPFS json-rpc or InfluxDB API)",
|
|
"tcpwrapped syn-ack ttl 56"
|
|
],
|
|
"exploit_precondition": "Validate affected product/version and exploit path prerequisites before filing.",
|
|
"reproducibility": "not-reproduced",
|
|
"disposition": "needs-manual-test",
|
|
"disposition_rationale": "Script/banner evidence exists, but no direct proof of exploit impact was captured in scan output.",
|
|
"required_reproduction_step_before_ticket": "Before creating a ticket, reproduce vulnerable behavior directly (e.g., crafted request causing data exposure, traversal read, or exploitable crash) and attach request/response proof. Banner or script signature matches alone are insufficient.",
|
|
"evidence_sources": [
|
|
{
|
|
"file": "results/auth.lan.ddnsgeek.com/scans/_patterns.log",
|
|
"match_count": 1
|
|
}
|
|
]
|
|
},
|
|
{
|
|
"host": "auth.lan.ddnsgeek.com",
|
|
"cve": "CVE-1999-0407",
|
|
"affected_host": "auth.lan.ddnsgeek.com",
|
|
"endpoint": "unknown",
|
|
"product_version_evidence": [
|
|
"http syn-ack ttl 55 Golang net/http server (Go-IPFS json-rpc or InfluxDB API)",
|
|
"http syn-ack ttl 55 Golang net/http server (Go-IPFS json-rpc or InfluxDB API)",
|
|
"http syn-ack ttl 55 Golang net/http server (Go-IPFS json-rpc or InfluxDB API)",
|
|
"ssl/http syn-ack ttl 55 Golang net/http server (Go-IPFS json-rpc or InfluxDB API)",
|
|
"ssl/http syn-ack ttl 55 Golang net/http server (Go-IPFS json-rpc or InfluxDB API)",
|
|
"tcpwrapped syn-ack ttl 56"
|
|
],
|
|
"exploit_precondition": "Validate affected product/version and exploit path prerequisites before filing.",
|
|
"reproducibility": "not-reproduced",
|
|
"disposition": "needs-manual-test",
|
|
"disposition_rationale": "Script/banner evidence exists, but no direct proof of exploit impact was captured in scan output.",
|
|
"required_reproduction_step_before_ticket": "Before creating a ticket, reproduce vulnerable behavior directly (e.g., crafted request causing data exposure, traversal read, or exploitable crash) and attach request/response proof. Banner or script signature matches alone are insufficient.",
|
|
"evidence_sources": [
|
|
{
|
|
"file": "results/auth.lan.ddnsgeek.com/scans/_patterns.log",
|
|
"match_count": 5
|
|
}
|
|
]
|
|
},
|
|
{
|
|
"host": "auth.lan.ddnsgeek.com",
|
|
"cve": "CVE-1999-0449",
|
|
"affected_host": "auth.lan.ddnsgeek.com",
|
|
"endpoint": "unknown",
|
|
"product_version_evidence": [
|
|
"http syn-ack ttl 55 Golang net/http server (Go-IPFS json-rpc or InfluxDB API)",
|
|
"http syn-ack ttl 55 Golang net/http server (Go-IPFS json-rpc or InfluxDB API)",
|
|
"http syn-ack ttl 55 Golang net/http server (Go-IPFS json-rpc or InfluxDB API)",
|
|
"ssl/http syn-ack ttl 55 Golang net/http server (Go-IPFS json-rpc or InfluxDB API)",
|
|
"ssl/http syn-ack ttl 55 Golang net/http server (Go-IPFS json-rpc or InfluxDB API)",
|
|
"tcpwrapped syn-ack ttl 56"
|
|
],
|
|
"exploit_precondition": "Validate affected product/version and exploit path prerequisites before filing.",
|
|
"reproducibility": "not-reproduced",
|
|
"disposition": "needs-manual-test",
|
|
"disposition_rationale": "Script/banner evidence exists, but no direct proof of exploit impact was captured in scan output.",
|
|
"required_reproduction_step_before_ticket": "Before creating a ticket, reproduce vulnerable behavior directly (e.g., crafted request causing data exposure, traversal read, or exploitable crash) and attach request/response proof. Banner or script signature matches alone are insufficient.",
|
|
"evidence_sources": [
|
|
{
|
|
"file": "results/auth.lan.ddnsgeek.com/scans/_patterns.log",
|
|
"match_count": 5
|
|
}
|
|
]
|
|
},
|
|
{
|
|
"host": "auth.lan.ddnsgeek.com",
|
|
"cve": "CVE-1999-0606",
|
|
"affected_host": "auth.lan.ddnsgeek.com",
|
|
"endpoint": "unknown",
|
|
"product_version_evidence": [
|
|
"http syn-ack ttl 55 Golang net/http server (Go-IPFS json-rpc or InfluxDB API)",
|
|
"http syn-ack ttl 55 Golang net/http server (Go-IPFS json-rpc or InfluxDB API)",
|
|
"http syn-ack ttl 55 Golang net/http server (Go-IPFS json-rpc or InfluxDB API)",
|
|
"ssl/http syn-ack ttl 55 Golang net/http server (Go-IPFS json-rpc or InfluxDB API)",
|
|
"ssl/http syn-ack ttl 55 Golang net/http server (Go-IPFS json-rpc or InfluxDB API)",
|
|
"tcpwrapped syn-ack ttl 56"
|
|
],
|
|
"exploit_precondition": "Validate affected product/version and exploit path prerequisites before filing.",
|
|
"reproducibility": "not-reproduced",
|
|
"disposition": "needs-manual-test",
|
|
"disposition_rationale": "Script/banner evidence exists, but no direct proof of exploit impact was captured in scan output.",
|
|
"required_reproduction_step_before_ticket": "Before creating a ticket, reproduce vulnerable behavior directly (e.g., crafted request causing data exposure, traversal read, or exploitable crash) and attach request/response proof. Banner or script signature matches alone are insufficient.",
|
|
"evidence_sources": [
|
|
{
|
|
"file": "results/auth.lan.ddnsgeek.com/scans/_patterns.log",
|
|
"match_count": 3
|
|
}
|
|
]
|
|
},
|
|
{
|
|
"host": "auth.lan.ddnsgeek.com",
|
|
"cve": "CVE-1999-0607",
|
|
"affected_host": "auth.lan.ddnsgeek.com",
|
|
"endpoint": "unknown",
|
|
"product_version_evidence": [
|
|
"http syn-ack ttl 55 Golang net/http server (Go-IPFS json-rpc or InfluxDB API)",
|
|
"http syn-ack ttl 55 Golang net/http server (Go-IPFS json-rpc or InfluxDB API)",
|
|
"http syn-ack ttl 55 Golang net/http server (Go-IPFS json-rpc or InfluxDB API)",
|
|
"ssl/http syn-ack ttl 55 Golang net/http server (Go-IPFS json-rpc or InfluxDB API)",
|
|
"ssl/http syn-ack ttl 55 Golang net/http server (Go-IPFS json-rpc or InfluxDB API)",
|
|
"tcpwrapped syn-ack ttl 56"
|
|
],
|
|
"exploit_precondition": "Validate affected product/version and exploit path prerequisites before filing.",
|
|
"reproducibility": "not-reproduced",
|
|
"disposition": "needs-manual-test",
|
|
"disposition_rationale": "Script/banner evidence exists, but no direct proof of exploit impact was captured in scan output.",
|
|
"required_reproduction_step_before_ticket": "Before creating a ticket, reproduce vulnerable behavior directly (e.g., crafted request causing data exposure, traversal read, or exploitable crash) and attach request/response proof. Banner or script signature matches alone are insufficient.",
|
|
"evidence_sources": [
|
|
{
|
|
"file": "results/auth.lan.ddnsgeek.com/scans/_patterns.log",
|
|
"match_count": 1
|
|
}
|
|
]
|
|
},
|
|
{
|
|
"host": "auth.lan.ddnsgeek.com",
|
|
"cve": "CVE-1999-0609",
|
|
"affected_host": "auth.lan.ddnsgeek.com",
|
|
"endpoint": "unknown",
|
|
"product_version_evidence": [
|
|
"http syn-ack ttl 55 Golang net/http server (Go-IPFS json-rpc or InfluxDB API)",
|
|
"http syn-ack ttl 55 Golang net/http server (Go-IPFS json-rpc or InfluxDB API)",
|
|
"http syn-ack ttl 55 Golang net/http server (Go-IPFS json-rpc or InfluxDB API)",
|
|
"ssl/http syn-ack ttl 55 Golang net/http server (Go-IPFS json-rpc or InfluxDB API)",
|
|
"ssl/http syn-ack ttl 55 Golang net/http server (Go-IPFS json-rpc or InfluxDB API)",
|
|
"tcpwrapped syn-ack ttl 56"
|
|
],
|
|
"exploit_precondition": "Validate affected product/version and exploit path prerequisites before filing.",
|
|
"reproducibility": "not-reproduced",
|
|
"disposition": "needs-manual-test",
|
|
"disposition_rationale": "Script/banner evidence exists, but no direct proof of exploit impact was captured in scan output.",
|
|
"required_reproduction_step_before_ticket": "Before creating a ticket, reproduce vulnerable behavior directly (e.g., crafted request causing data exposure, traversal read, or exploitable crash) and attach request/response proof. Banner or script signature matches alone are insufficient.",
|
|
"evidence_sources": [
|
|
{
|
|
"file": "results/auth.lan.ddnsgeek.com/scans/_patterns.log",
|
|
"match_count": 1
|
|
}
|
|
]
|
|
},
|
|
{
|
|
"host": "auth.lan.ddnsgeek.com",
|
|
"cve": "CVE-1999-0678",
|
|
"affected_host": "auth.lan.ddnsgeek.com",
|
|
"endpoint": "unknown",
|
|
"product_version_evidence": [
|
|
"http syn-ack ttl 55 Golang net/http server (Go-IPFS json-rpc or InfluxDB API)",
|
|
"http syn-ack ttl 55 Golang net/http server (Go-IPFS json-rpc or InfluxDB API)",
|
|
"http syn-ack ttl 55 Golang net/http server (Go-IPFS json-rpc or InfluxDB API)",
|
|
"ssl/http syn-ack ttl 55 Golang net/http server (Go-IPFS json-rpc or InfluxDB API)",
|
|
"ssl/http syn-ack ttl 55 Golang net/http server (Go-IPFS json-rpc or InfluxDB API)",
|
|
"tcpwrapped syn-ack ttl 56"
|
|
],
|
|
"exploit_precondition": "Validate affected product/version and exploit path prerequisites before filing.",
|
|
"reproducibility": "not-reproduced",
|
|
"disposition": "needs-manual-test",
|
|
"disposition_rationale": "Script/banner evidence exists, but no direct proof of exploit impact was captured in scan output.",
|
|
"required_reproduction_step_before_ticket": "Before creating a ticket, reproduce vulnerable behavior directly (e.g., crafted request causing data exposure, traversal read, or exploitable crash) and attach request/response proof. Banner or script signature matches alone are insufficient.",
|
|
"evidence_sources": [
|
|
{
|
|
"file": "results/auth.lan.ddnsgeek.com/scans/_patterns.log",
|
|
"match_count": 2
|
|
}
|
|
]
|
|
},
|
|
{
|
|
"host": "auth.lan.ddnsgeek.com",
|
|
"cve": "CVE-1999-0737",
|
|
"affected_host": "auth.lan.ddnsgeek.com",
|
|
"endpoint": "unknown",
|
|
"product_version_evidence": [
|
|
"http syn-ack ttl 55 Golang net/http server (Go-IPFS json-rpc or InfluxDB API)",
|
|
"http syn-ack ttl 55 Golang net/http server (Go-IPFS json-rpc or InfluxDB API)",
|
|
"http syn-ack ttl 55 Golang net/http server (Go-IPFS json-rpc or InfluxDB API)",
|
|
"ssl/http syn-ack ttl 55 Golang net/http server (Go-IPFS json-rpc or InfluxDB API)",
|
|
"ssl/http syn-ack ttl 55 Golang net/http server (Go-IPFS json-rpc or InfluxDB API)",
|
|
"tcpwrapped syn-ack ttl 56"
|
|
],
|
|
"exploit_precondition": "Validate affected product/version and exploit path prerequisites before filing.",
|
|
"reproducibility": "not-reproduced",
|
|
"disposition": "needs-manual-test",
|
|
"disposition_rationale": "Script/banner evidence exists, but no direct proof of exploit impact was captured in scan output.",
|
|
"required_reproduction_step_before_ticket": "Before creating a ticket, reproduce vulnerable behavior directly (e.g., crafted request causing data exposure, traversal read, or exploitable crash) and attach request/response proof. Banner or script signature matches alone are insufficient.",
|
|
"evidence_sources": [
|
|
{
|
|
"file": "results/auth.lan.ddnsgeek.com/scans/_patterns.log",
|
|
"match_count": 7
|
|
}
|
|
]
|
|
},
|
|
{
|
|
"host": "auth.lan.ddnsgeek.com",
|
|
"cve": "CVE-1999-0738",
|
|
"affected_host": "auth.lan.ddnsgeek.com",
|
|
"endpoint": "unknown",
|
|
"product_version_evidence": [
|
|
"http syn-ack ttl 55 Golang net/http server (Go-IPFS json-rpc or InfluxDB API)",
|
|
"http syn-ack ttl 55 Golang net/http server (Go-IPFS json-rpc or InfluxDB API)",
|
|
"http syn-ack ttl 55 Golang net/http server (Go-IPFS json-rpc or InfluxDB API)",
|
|
"ssl/http syn-ack ttl 55 Golang net/http server (Go-IPFS json-rpc or InfluxDB API)",
|
|
"ssl/http syn-ack ttl 55 Golang net/http server (Go-IPFS json-rpc or InfluxDB API)",
|
|
"tcpwrapped syn-ack ttl 56"
|
|
],
|
|
"exploit_precondition": "Validate affected product/version and exploit path prerequisites before filing.",
|
|
"reproducibility": "not-reproduced",
|
|
"disposition": "needs-manual-test",
|
|
"disposition_rationale": "Script/banner evidence exists, but no direct proof of exploit impact was captured in scan output.",
|
|
"required_reproduction_step_before_ticket": "Before creating a ticket, reproduce vulnerable behavior directly (e.g., crafted request causing data exposure, traversal read, or exploitable crash) and attach request/response proof. Banner or script signature matches alone are insufficient.",
|
|
"evidence_sources": [
|
|
{
|
|
"file": "results/auth.lan.ddnsgeek.com/scans/_patterns.log",
|
|
"match_count": 1
|
|
}
|
|
]
|
|
},
|
|
{
|
|
"host": "auth.lan.ddnsgeek.com",
|
|
"cve": "CVE-1999-0739",
|
|
"affected_host": "auth.lan.ddnsgeek.com",
|
|
"endpoint": "unknown",
|
|
"product_version_evidence": [
|
|
"http syn-ack ttl 55 Golang net/http server (Go-IPFS json-rpc or InfluxDB API)",
|
|
"http syn-ack ttl 55 Golang net/http server (Go-IPFS json-rpc or InfluxDB API)",
|
|
"http syn-ack ttl 55 Golang net/http server (Go-IPFS json-rpc or InfluxDB API)",
|
|
"ssl/http syn-ack ttl 55 Golang net/http server (Go-IPFS json-rpc or InfluxDB API)",
|
|
"ssl/http syn-ack ttl 55 Golang net/http server (Go-IPFS json-rpc or InfluxDB API)",
|
|
"tcpwrapped syn-ack ttl 56"
|
|
],
|
|
"exploit_precondition": "Validate affected product/version and exploit path prerequisites before filing.",
|
|
"reproducibility": "not-reproduced",
|
|
"disposition": "needs-manual-test",
|
|
"disposition_rationale": "Script/banner evidence exists, but no direct proof of exploit impact was captured in scan output.",
|
|
"required_reproduction_step_before_ticket": "Before creating a ticket, reproduce vulnerable behavior directly (e.g., crafted request causing data exposure, traversal read, or exploitable crash) and attach request/response proof. Banner or script signature matches alone are insufficient.",
|
|
"evidence_sources": [
|
|
{
|
|
"file": "results/auth.lan.ddnsgeek.com/scans/_patterns.log",
|
|
"match_count": 3
|
|
}
|
|
]
|
|
},
|
|
{
|
|
"host": "auth.lan.ddnsgeek.com",
|
|
"cve": "CVE-1999-0930",
|
|
"affected_host": "auth.lan.ddnsgeek.com",
|
|
"endpoint": "unknown",
|
|
"product_version_evidence": [
|
|
"http syn-ack ttl 55 Golang net/http server (Go-IPFS json-rpc or InfluxDB API)",
|
|
"http syn-ack ttl 55 Golang net/http server (Go-IPFS json-rpc or InfluxDB API)",
|
|
"http syn-ack ttl 55 Golang net/http server (Go-IPFS json-rpc or InfluxDB API)",
|
|
"ssl/http syn-ack ttl 55 Golang net/http server (Go-IPFS json-rpc or InfluxDB API)",
|
|
"ssl/http syn-ack ttl 55 Golang net/http server (Go-IPFS json-rpc or InfluxDB API)",
|
|
"tcpwrapped syn-ack ttl 56"
|
|
],
|
|
"exploit_precondition": "Validate affected product/version and exploit path prerequisites before filing.",
|
|
"reproducibility": "not-reproduced",
|
|
"disposition": "needs-manual-test",
|
|
"disposition_rationale": "Script/banner evidence exists, but no direct proof of exploit impact was captured in scan output.",
|
|
"required_reproduction_step_before_ticket": "Before creating a ticket, reproduce vulnerable behavior directly (e.g., crafted request causing data exposure, traversal read, or exploitable crash) and attach request/response proof. Banner or script signature matches alone are insufficient.",
|
|
"evidence_sources": [
|
|
{
|
|
"file": "results/auth.lan.ddnsgeek.com/scans/_patterns.log",
|
|
"match_count": 3
|
|
}
|
|
]
|
|
},
|
|
{
|
|
"host": "auth.lan.ddnsgeek.com",
|
|
"cve": "CVE-1999-1011",
|
|
"affected_host": "auth.lan.ddnsgeek.com",
|
|
"endpoint": "unknown",
|
|
"product_version_evidence": [
|
|
"http syn-ack ttl 55 Golang net/http server (Go-IPFS json-rpc or InfluxDB API)",
|
|
"http syn-ack ttl 55 Golang net/http server (Go-IPFS json-rpc or InfluxDB API)",
|
|
"http syn-ack ttl 55 Golang net/http server (Go-IPFS json-rpc or InfluxDB API)",
|
|
"ssl/http syn-ack ttl 55 Golang net/http server (Go-IPFS json-rpc or InfluxDB API)",
|
|
"ssl/http syn-ack ttl 55 Golang net/http server (Go-IPFS json-rpc or InfluxDB API)",
|
|
"tcpwrapped syn-ack ttl 56"
|
|
],
|
|
"exploit_precondition": "Validate affected product/version and exploit path prerequisites before filing.",
|
|
"reproducibility": "not-reproduced",
|
|
"disposition": "needs-manual-test",
|
|
"disposition_rationale": "Script/banner evidence exists, but no direct proof of exploit impact was captured in scan output.",
|
|
"required_reproduction_step_before_ticket": "Before creating a ticket, reproduce vulnerable behavior directly (e.g., crafted request causing data exposure, traversal read, or exploitable crash) and attach request/response proof. Banner or script signature matches alone are insufficient.",
|
|
"evidence_sources": [
|
|
{
|
|
"file": "results/auth.lan.ddnsgeek.com/scans/_patterns.log",
|
|
"match_count": 1
|
|
}
|
|
]
|
|
},
|
|
{
|
|
"host": "auth.lan.ddnsgeek.com",
|
|
"cve": "CVE-1999-1052",
|
|
"affected_host": "auth.lan.ddnsgeek.com",
|
|
"endpoint": "unknown",
|
|
"product_version_evidence": [
|
|
"http syn-ack ttl 55 Golang net/http server (Go-IPFS json-rpc or InfluxDB API)",
|
|
"http syn-ack ttl 55 Golang net/http server (Go-IPFS json-rpc or InfluxDB API)",
|
|
"http syn-ack ttl 55 Golang net/http server (Go-IPFS json-rpc or InfluxDB API)",
|
|
"ssl/http syn-ack ttl 55 Golang net/http server (Go-IPFS json-rpc or InfluxDB API)",
|
|
"ssl/http syn-ack ttl 55 Golang net/http server (Go-IPFS json-rpc or InfluxDB API)",
|
|
"tcpwrapped syn-ack ttl 56"
|
|
],
|
|
"exploit_precondition": "Validate affected product/version and exploit path prerequisites before filing.",
|
|
"reproducibility": "not-reproduced",
|
|
"disposition": "needs-manual-test",
|
|
"disposition_rationale": "Script/banner evidence exists, but no direct proof of exploit impact was captured in scan output.",
|
|
"required_reproduction_step_before_ticket": "Before creating a ticket, reproduce vulnerable behavior directly (e.g., crafted request causing data exposure, traversal read, or exploitable crash) and attach request/response proof. Banner or script signature matches alone are insufficient.",
|
|
"evidence_sources": [
|
|
{
|
|
"file": "results/auth.lan.ddnsgeek.com/scans/_patterns.log",
|
|
"match_count": 3
|
|
}
|
|
]
|
|
},
|
|
{
|
|
"host": "auth.lan.ddnsgeek.com",
|
|
"cve": "CVE-1999-1508",
|
|
"affected_host": "auth.lan.ddnsgeek.com",
|
|
"endpoint": "unknown",
|
|
"product_version_evidence": [
|
|
"http syn-ack ttl 55 Golang net/http server (Go-IPFS json-rpc or InfluxDB API)",
|
|
"http syn-ack ttl 55 Golang net/http server (Go-IPFS json-rpc or InfluxDB API)",
|
|
"http syn-ack ttl 55 Golang net/http server (Go-IPFS json-rpc or InfluxDB API)",
|
|
"ssl/http syn-ack ttl 55 Golang net/http server (Go-IPFS json-rpc or InfluxDB API)",
|
|
"ssl/http syn-ack ttl 55 Golang net/http server (Go-IPFS json-rpc or InfluxDB API)",
|
|
"tcpwrapped syn-ack ttl 56"
|
|
],
|
|
"exploit_precondition": "Validate affected product/version and exploit path prerequisites before filing.",
|
|
"reproducibility": "not-reproduced",
|
|
"disposition": "needs-manual-test",
|
|
"disposition_rationale": "Script/banner evidence exists, but no direct proof of exploit impact was captured in scan output.",
|
|
"required_reproduction_step_before_ticket": "Before creating a ticket, reproduce vulnerable behavior directly (e.g., crafted request causing data exposure, traversal read, or exploitable crash) and attach request/response proof. Banner or script signature matches alone are insufficient.",
|
|
"evidence_sources": [
|
|
{
|
|
"file": "results/auth.lan.ddnsgeek.com/scans/_patterns.log",
|
|
"match_count": 1
|
|
}
|
|
]
|
|
},
|
|
{
|
|
"host": "auth.lan.ddnsgeek.com",
|
|
"cve": "CVE-1999-1520",
|
|
"affected_host": "auth.lan.ddnsgeek.com",
|
|
"endpoint": "unknown",
|
|
"product_version_evidence": [
|
|
"http syn-ack ttl 55 Golang net/http server (Go-IPFS json-rpc or InfluxDB API)",
|
|
"http syn-ack ttl 55 Golang net/http server (Go-IPFS json-rpc or InfluxDB API)",
|
|
"http syn-ack ttl 55 Golang net/http server (Go-IPFS json-rpc or InfluxDB API)",
|
|
"ssl/http syn-ack ttl 55 Golang net/http server (Go-IPFS json-rpc or InfluxDB API)",
|
|
"ssl/http syn-ack ttl 55 Golang net/http server (Go-IPFS json-rpc or InfluxDB API)",
|
|
"tcpwrapped syn-ack ttl 56"
|
|
],
|
|
"exploit_precondition": "Validate affected product/version and exploit path prerequisites before filing.",
|
|
"reproducibility": "not-reproduced",
|
|
"disposition": "needs-manual-test",
|
|
"disposition_rationale": "Script/banner evidence exists, but no direct proof of exploit impact was captured in scan output.",
|
|
"required_reproduction_step_before_ticket": "Before creating a ticket, reproduce vulnerable behavior directly (e.g., crafted request causing data exposure, traversal read, or exploitable crash) and attach request/response proof. Banner or script signature matches alone are insufficient.",
|
|
"evidence_sources": [
|
|
{
|
|
"file": "results/auth.lan.ddnsgeek.com/scans/_patterns.log",
|
|
"match_count": 1
|
|
}
|
|
]
|
|
},
|
|
{
|
|
"host": "auth.lan.ddnsgeek.com",
|
|
"cve": "CVE-1999-1550",
|
|
"affected_host": "auth.lan.ddnsgeek.com",
|
|
"endpoint": "unknown",
|
|
"product_version_evidence": [
|
|
"http syn-ack ttl 55 Golang net/http server (Go-IPFS json-rpc or InfluxDB API)",
|
|
"http syn-ack ttl 55 Golang net/http server (Go-IPFS json-rpc or InfluxDB API)",
|
|
"http syn-ack ttl 55 Golang net/http server (Go-IPFS json-rpc or InfluxDB API)",
|
|
"ssl/http syn-ack ttl 55 Golang net/http server (Go-IPFS json-rpc or InfluxDB API)",
|
|
"ssl/http syn-ack ttl 55 Golang net/http server (Go-IPFS json-rpc or InfluxDB API)",
|
|
"tcpwrapped syn-ack ttl 56"
|
|
],
|
|
"exploit_precondition": "Validate affected product/version and exploit path prerequisites before filing.",
|
|
"reproducibility": "not-reproduced",
|
|
"disposition": "needs-manual-test",
|
|
"disposition_rationale": "Script/banner evidence exists, but no direct proof of exploit impact was captured in scan output.",
|
|
"required_reproduction_step_before_ticket": "Before creating a ticket, reproduce vulnerable behavior directly (e.g., crafted request causing data exposure, traversal read, or exploitable crash) and attach request/response proof. Banner or script signature matches alone are insufficient.",
|
|
"evidence_sources": [
|
|
{
|
|
"file": "results/auth.lan.ddnsgeek.com/scans/_patterns.log",
|
|
"match_count": 1
|
|
}
|
|
]
|
|
},
|
|
{
|
|
"host": "auth.lan.ddnsgeek.com",
|
|
"cve": "CVE-2000-0063",
|
|
"affected_host": "auth.lan.ddnsgeek.com",
|
|
"endpoint": "unknown",
|
|
"product_version_evidence": [
|
|
"http syn-ack ttl 55 Golang net/http server (Go-IPFS json-rpc or InfluxDB API)",
|
|
"http syn-ack ttl 55 Golang net/http server (Go-IPFS json-rpc or InfluxDB API)",
|
|
"http syn-ack ttl 55 Golang net/http server (Go-IPFS json-rpc or InfluxDB API)",
|
|
"ssl/http syn-ack ttl 55 Golang net/http server (Go-IPFS json-rpc or InfluxDB API)",
|
|
"ssl/http syn-ack ttl 55 Golang net/http server (Go-IPFS json-rpc or InfluxDB API)",
|
|
"tcpwrapped syn-ack ttl 56"
|
|
],
|
|
"exploit_precondition": "Validate affected product/version and exploit path prerequisites before filing.",
|
|
"reproducibility": "not-reproduced",
|
|
"disposition": "needs-manual-test",
|
|
"disposition_rationale": "Script/banner evidence exists, but no direct proof of exploit impact was captured in scan output.",
|
|
"required_reproduction_step_before_ticket": "Before creating a ticket, reproduce vulnerable behavior directly (e.g., crafted request causing data exposure, traversal read, or exploitable crash) and attach request/response proof. Banner or script signature matches alone are insufficient.",
|
|
"evidence_sources": [
|
|
{
|
|
"file": "results/auth.lan.ddnsgeek.com/scans/_patterns.log",
|
|
"match_count": 1
|
|
}
|
|
]
|
|
},
|
|
{
|
|
"host": "auth.lan.ddnsgeek.com",
|
|
"cve": "CVE-2000-0127",
|
|
"affected_host": "auth.lan.ddnsgeek.com",
|
|
"endpoint": "unknown",
|
|
"product_version_evidence": [
|
|
"http syn-ack ttl 55 Golang net/http server (Go-IPFS json-rpc or InfluxDB API)",
|
|
"http syn-ack ttl 55 Golang net/http server (Go-IPFS json-rpc or InfluxDB API)",
|
|
"http syn-ack ttl 55 Golang net/http server (Go-IPFS json-rpc or InfluxDB API)",
|
|
"ssl/http syn-ack ttl 55 Golang net/http server (Go-IPFS json-rpc or InfluxDB API)",
|
|
"ssl/http syn-ack ttl 55 Golang net/http server (Go-IPFS json-rpc or InfluxDB API)",
|
|
"tcpwrapped syn-ack ttl 56"
|
|
],
|
|
"exploit_precondition": "Validate affected product/version and exploit path prerequisites before filing.",
|
|
"reproducibility": "not-reproduced",
|
|
"disposition": "needs-manual-test",
|
|
"disposition_rationale": "Script/banner evidence exists, but no direct proof of exploit impact was captured in scan output.",
|
|
"required_reproduction_step_before_ticket": "Before creating a ticket, reproduce vulnerable behavior directly (e.g., crafted request causing data exposure, traversal read, or exploitable crash) and attach request/response proof. Banner or script signature matches alone are insufficient.",
|
|
"evidence_sources": [
|
|
{
|
|
"file": "results/auth.lan.ddnsgeek.com/scans/_patterns.log",
|
|
"match_count": 1
|
|
}
|
|
]
|
|
},
|
|
{
|
|
"host": "auth.lan.ddnsgeek.com",
|
|
"cve": "CVE-2000-0237",
|
|
"affected_host": "auth.lan.ddnsgeek.com",
|
|
"endpoint": "unknown",
|
|
"product_version_evidence": [
|
|
"http syn-ack ttl 55 Golang net/http server (Go-IPFS json-rpc or InfluxDB API)",
|
|
"http syn-ack ttl 55 Golang net/http server (Go-IPFS json-rpc or InfluxDB API)",
|
|
"http syn-ack ttl 55 Golang net/http server (Go-IPFS json-rpc or InfluxDB API)",
|
|
"ssl/http syn-ack ttl 55 Golang net/http server (Go-IPFS json-rpc or InfluxDB API)",
|
|
"ssl/http syn-ack ttl 55 Golang net/http server (Go-IPFS json-rpc or InfluxDB API)",
|
|
"tcpwrapped syn-ack ttl 56"
|
|
],
|
|
"exploit_precondition": "Validate affected product/version and exploit path prerequisites before filing.",
|
|
"reproducibility": "not-reproduced",
|
|
"disposition": "needs-manual-test",
|
|
"disposition_rationale": "Script/banner evidence exists, but no direct proof of exploit impact was captured in scan output.",
|
|
"required_reproduction_step_before_ticket": "Before creating a ticket, reproduce vulnerable behavior directly (e.g., crafted request causing data exposure, traversal read, or exploitable crash) and attach request/response proof. Banner or script signature matches alone are insufficient.",
|
|
"evidence_sources": [
|
|
{
|
|
"file": "results/auth.lan.ddnsgeek.com/scans/_patterns.log",
|
|
"match_count": 1
|
|
}
|
|
]
|
|
},
|
|
{
|
|
"host": "auth.lan.ddnsgeek.com",
|
|
"cve": "CVE-2000-0413",
|
|
"affected_host": "auth.lan.ddnsgeek.com",
|
|
"endpoint": "unknown",
|
|
"product_version_evidence": [
|
|
"http syn-ack ttl 55 Golang net/http server (Go-IPFS json-rpc or InfluxDB API)",
|
|
"http syn-ack ttl 55 Golang net/http server (Go-IPFS json-rpc or InfluxDB API)",
|
|
"http syn-ack ttl 55 Golang net/http server (Go-IPFS json-rpc or InfluxDB API)",
|
|
"ssl/http syn-ack ttl 55 Golang net/http server (Go-IPFS json-rpc or InfluxDB API)",
|
|
"ssl/http syn-ack ttl 55 Golang net/http server (Go-IPFS json-rpc or InfluxDB API)",
|
|
"tcpwrapped syn-ack ttl 56"
|
|
],
|
|
"exploit_precondition": "Validate affected product/version and exploit path prerequisites before filing.",
|
|
"reproducibility": "not-reproduced",
|
|
"disposition": "needs-manual-test",
|
|
"disposition_rationale": "Script/banner evidence exists, but no direct proof of exploit impact was captured in scan output.",
|
|
"required_reproduction_step_before_ticket": "Before creating a ticket, reproduce vulnerable behavior directly (e.g., crafted request causing data exposure, traversal read, or exploitable crash) and attach request/response proof. Banner or script signature matches alone are insufficient.",
|
|
"evidence_sources": [
|
|
{
|
|
"file": "results/auth.lan.ddnsgeek.com/scans/_patterns.log",
|
|
"match_count": 2
|
|
}
|
|
]
|
|
},
|
|
{
|
|
"host": "auth.lan.ddnsgeek.com",
|
|
"cve": "CVE-2000-0429",
|
|
"affected_host": "auth.lan.ddnsgeek.com",
|
|
"endpoint": "unknown",
|
|
"product_version_evidence": [
|
|
"http syn-ack ttl 55 Golang net/http server (Go-IPFS json-rpc or InfluxDB API)",
|
|
"http syn-ack ttl 55 Golang net/http server (Go-IPFS json-rpc or InfluxDB API)",
|
|
"http syn-ack ttl 55 Golang net/http server (Go-IPFS json-rpc or InfluxDB API)",
|
|
"ssl/http syn-ack ttl 55 Golang net/http server (Go-IPFS json-rpc or InfluxDB API)",
|
|
"ssl/http syn-ack ttl 55 Golang net/http server (Go-IPFS json-rpc or InfluxDB API)",
|
|
"tcpwrapped syn-ack ttl 56"
|
|
],
|
|
"exploit_precondition": "Validate affected product/version and exploit path prerequisites before filing.",
|
|
"reproducibility": "not-reproduced",
|
|
"disposition": "needs-manual-test",
|
|
"disposition_rationale": "Script/banner evidence exists, but no direct proof of exploit impact was captured in scan output.",
|
|
"required_reproduction_step_before_ticket": "Before creating a ticket, reproduce vulnerable behavior directly (e.g., crafted request causing data exposure, traversal read, or exploitable crash) and attach request/response proof. Banner or script signature matches alone are insufficient.",
|
|
"evidence_sources": [
|
|
{
|
|
"file": "results/auth.lan.ddnsgeek.com/scans/_patterns.log",
|
|
"match_count": 1
|
|
}
|
|
]
|
|
},
|
|
{
|
|
"host": "auth.lan.ddnsgeek.com",
|
|
"cve": "CVE-2000-0628",
|
|
"affected_host": "auth.lan.ddnsgeek.com",
|
|
"endpoint": "unknown",
|
|
"product_version_evidence": [
|
|
"http syn-ack ttl 55 Golang net/http server (Go-IPFS json-rpc or InfluxDB API)",
|
|
"http syn-ack ttl 55 Golang net/http server (Go-IPFS json-rpc or InfluxDB API)",
|
|
"http syn-ack ttl 55 Golang net/http server (Go-IPFS json-rpc or InfluxDB API)",
|
|
"ssl/http syn-ack ttl 55 Golang net/http server (Go-IPFS json-rpc or InfluxDB API)",
|
|
"ssl/http syn-ack ttl 55 Golang net/http server (Go-IPFS json-rpc or InfluxDB API)",
|
|
"tcpwrapped syn-ack ttl 56"
|
|
],
|
|
"exploit_precondition": "Validate affected product/version and exploit path prerequisites before filing.",
|
|
"reproducibility": "not-reproduced",
|
|
"disposition": "needs-manual-test",
|
|
"disposition_rationale": "Script/banner evidence exists, but no direct proof of exploit impact was captured in scan output.",
|
|
"required_reproduction_step_before_ticket": "Before creating a ticket, reproduce vulnerable behavior directly (e.g., crafted request causing data exposure, traversal read, or exploitable crash) and attach request/response proof. Banner or script signature matches alone are insufficient.",
|
|
"evidence_sources": [
|
|
{
|
|
"file": "results/auth.lan.ddnsgeek.com/scans/_patterns.log",
|
|
"match_count": 1
|
|
}
|
|
]
|
|
},
|
|
{
|
|
"host": "auth.lan.ddnsgeek.com",
|
|
"cve": "CVE-2000-0672",
|
|
"affected_host": "auth.lan.ddnsgeek.com",
|
|
"endpoint": "unknown",
|
|
"product_version_evidence": [
|
|
"http syn-ack ttl 55 Golang net/http server (Go-IPFS json-rpc or InfluxDB API)",
|
|
"http syn-ack ttl 55 Golang net/http server (Go-IPFS json-rpc or InfluxDB API)",
|
|
"http syn-ack ttl 55 Golang net/http server (Go-IPFS json-rpc or InfluxDB API)",
|
|
"ssl/http syn-ack ttl 55 Golang net/http server (Go-IPFS json-rpc or InfluxDB API)",
|
|
"ssl/http syn-ack ttl 55 Golang net/http server (Go-IPFS json-rpc or InfluxDB API)",
|
|
"tcpwrapped syn-ack ttl 56"
|
|
],
|
|
"exploit_precondition": "Validate affected product/version and exploit path prerequisites before filing.",
|
|
"reproducibility": "not-reproduced",
|
|
"disposition": "needs-manual-test",
|
|
"disposition_rationale": "Script/banner evidence exists, but no direct proof of exploit impact was captured in scan output.",
|
|
"required_reproduction_step_before_ticket": "Before creating a ticket, reproduce vulnerable behavior directly (e.g., crafted request causing data exposure, traversal read, or exploitable crash) and attach request/response proof. Banner or script signature matches alone are insufficient.",
|
|
"evidence_sources": [
|
|
{
|
|
"file": "results/auth.lan.ddnsgeek.com/scans/_patterns.log",
|
|
"match_count": 5
|
|
}
|
|
]
|
|
},
|
|
{
|
|
"host": "auth.lan.ddnsgeek.com",
|
|
"cve": "CVE-2000-0696",
|
|
"affected_host": "auth.lan.ddnsgeek.com",
|
|
"endpoint": "unknown",
|
|
"product_version_evidence": [
|
|
"http syn-ack ttl 55 Golang net/http server (Go-IPFS json-rpc or InfluxDB API)",
|
|
"http syn-ack ttl 55 Golang net/http server (Go-IPFS json-rpc or InfluxDB API)",
|
|
"http syn-ack ttl 55 Golang net/http server (Go-IPFS json-rpc or InfluxDB API)",
|
|
"ssl/http syn-ack ttl 55 Golang net/http server (Go-IPFS json-rpc or InfluxDB API)",
|
|
"ssl/http syn-ack ttl 55 Golang net/http server (Go-IPFS json-rpc or InfluxDB API)",
|
|
"tcpwrapped syn-ack ttl 56"
|
|
],
|
|
"exploit_precondition": "Validate affected product/version and exploit path prerequisites before filing.",
|
|
"reproducibility": "not-reproduced",
|
|
"disposition": "needs-manual-test",
|
|
"disposition_rationale": "Script/banner evidence exists, but no direct proof of exploit impact was captured in scan output.",
|
|
"required_reproduction_step_before_ticket": "Before creating a ticket, reproduce vulnerable behavior directly (e.g., crafted request causing data exposure, traversal read, or exploitable crash) and attach request/response proof. Banner or script signature matches alone are insufficient.",
|
|
"evidence_sources": [
|
|
{
|
|
"file": "results/auth.lan.ddnsgeek.com/scans/_patterns.log",
|
|
"match_count": 1
|
|
}
|
|
]
|
|
},
|
|
{
|
|
"host": "auth.lan.ddnsgeek.com",
|
|
"cve": "CVE-2000-0709",
|
|
"affected_host": "auth.lan.ddnsgeek.com",
|
|
"endpoint": "unknown",
|
|
"product_version_evidence": [
|
|
"http syn-ack ttl 55 Golang net/http server (Go-IPFS json-rpc or InfluxDB API)",
|
|
"http syn-ack ttl 55 Golang net/http server (Go-IPFS json-rpc or InfluxDB API)",
|
|
"http syn-ack ttl 55 Golang net/http server (Go-IPFS json-rpc or InfluxDB API)",
|
|
"ssl/http syn-ack ttl 55 Golang net/http server (Go-IPFS json-rpc or InfluxDB API)",
|
|
"ssl/http syn-ack ttl 55 Golang net/http server (Go-IPFS json-rpc or InfluxDB API)",
|
|
"tcpwrapped syn-ack ttl 56"
|
|
],
|
|
"exploit_precondition": "Validate affected product/version and exploit path prerequisites before filing.",
|
|
"reproducibility": "not-reproduced",
|
|
"disposition": "needs-manual-test",
|
|
"disposition_rationale": "Script/banner evidence exists, but no direct proof of exploit impact was captured in scan output.",
|
|
"required_reproduction_step_before_ticket": "Before creating a ticket, reproduce vulnerable behavior directly (e.g., crafted request causing data exposure, traversal read, or exploitable crash) and attach request/response proof. Banner or script signature matches alone are insufficient.",
|
|
"evidence_sources": [
|
|
{
|
|
"file": "results/auth.lan.ddnsgeek.com/scans/_patterns.log",
|
|
"match_count": 1
|
|
}
|
|
]
|
|
},
|
|
{
|
|
"host": "auth.lan.ddnsgeek.com",
|
|
"cve": "CVE-2001-0432",
|
|
"affected_host": "auth.lan.ddnsgeek.com",
|
|
"endpoint": "unknown",
|
|
"product_version_evidence": [
|
|
"http syn-ack ttl 55 Golang net/http server (Go-IPFS json-rpc or InfluxDB API)",
|
|
"http syn-ack ttl 55 Golang net/http server (Go-IPFS json-rpc or InfluxDB API)",
|
|
"http syn-ack ttl 55 Golang net/http server (Go-IPFS json-rpc or InfluxDB API)",
|
|
"ssl/http syn-ack ttl 55 Golang net/http server (Go-IPFS json-rpc or InfluxDB API)",
|
|
"ssl/http syn-ack ttl 55 Golang net/http server (Go-IPFS json-rpc or InfluxDB API)",
|
|
"tcpwrapped syn-ack ttl 56"
|
|
],
|
|
"exploit_precondition": "Validate affected product/version and exploit path prerequisites before filing.",
|
|
"reproducibility": "not-reproduced",
|
|
"disposition": "needs-manual-test",
|
|
"disposition_rationale": "Script/banner evidence exists, but no direct proof of exploit impact was captured in scan output.",
|
|
"required_reproduction_step_before_ticket": "Before creating a ticket, reproduce vulnerable behavior directly (e.g., crafted request causing data exposure, traversal read, or exploitable crash) and attach request/response proof. Banner or script signature matches alone are insufficient.",
|
|
"evidence_sources": [
|
|
{
|
|
"file": "results/auth.lan.ddnsgeek.com/scans/_patterns.log",
|
|
"match_count": 1
|
|
}
|
|
]
|
|
},
|
|
{
|
|
"host": "auth.lan.ddnsgeek.com",
|
|
"cve": "CVE-2001-0484",
|
|
"affected_host": "auth.lan.ddnsgeek.com",
|
|
"endpoint": "unknown",
|
|
"product_version_evidence": [
|
|
"http syn-ack ttl 55 Golang net/http server (Go-IPFS json-rpc or InfluxDB API)",
|
|
"http syn-ack ttl 55 Golang net/http server (Go-IPFS json-rpc or InfluxDB API)",
|
|
"http syn-ack ttl 55 Golang net/http server (Go-IPFS json-rpc or InfluxDB API)",
|
|
"ssl/http syn-ack ttl 55 Golang net/http server (Go-IPFS json-rpc or InfluxDB API)",
|
|
"ssl/http syn-ack ttl 55 Golang net/http server (Go-IPFS json-rpc or InfluxDB API)",
|
|
"tcpwrapped syn-ack ttl 56"
|
|
],
|
|
"exploit_precondition": "Validate affected product/version and exploit path prerequisites before filing.",
|
|
"reproducibility": "not-reproduced",
|
|
"disposition": "needs-manual-test",
|
|
"disposition_rationale": "Script/banner evidence exists, but no direct proof of exploit impact was captured in scan output.",
|
|
"required_reproduction_step_before_ticket": "Before creating a ticket, reproduce vulnerable behavior directly (e.g., crafted request causing data exposure, traversal read, or exploitable crash) and attach request/response proof. Banner or script signature matches alone are insufficient.",
|
|
"evidence_sources": [
|
|
{
|
|
"file": "results/auth.lan.ddnsgeek.com/scans/_patterns.log",
|
|
"match_count": 1
|
|
}
|
|
]
|
|
},
|
|
{
|
|
"host": "auth.lan.ddnsgeek.com",
|
|
"cve": "CVE-2001-0500",
|
|
"affected_host": "auth.lan.ddnsgeek.com",
|
|
"endpoint": "unknown",
|
|
"product_version_evidence": [
|
|
"http syn-ack ttl 55 Golang net/http server (Go-IPFS json-rpc or InfluxDB API)",
|
|
"http syn-ack ttl 55 Golang net/http server (Go-IPFS json-rpc or InfluxDB API)",
|
|
"http syn-ack ttl 55 Golang net/http server (Go-IPFS json-rpc or InfluxDB API)",
|
|
"ssl/http syn-ack ttl 55 Golang net/http server (Go-IPFS json-rpc or InfluxDB API)",
|
|
"ssl/http syn-ack ttl 55 Golang net/http server (Go-IPFS json-rpc or InfluxDB API)",
|
|
"tcpwrapped syn-ack ttl 56"
|
|
],
|
|
"exploit_precondition": "Validate affected product/version and exploit path prerequisites before filing.",
|
|
"reproducibility": "not-reproduced",
|
|
"disposition": "needs-manual-test",
|
|
"disposition_rationale": "Script/banner evidence exists, but no direct proof of exploit impact was captured in scan output.",
|
|
"required_reproduction_step_before_ticket": "Before creating a ticket, reproduce vulnerable behavior directly (e.g., crafted request causing data exposure, traversal read, or exploitable crash) and attach request/response proof. Banner or script signature matches alone are insufficient.",
|
|
"evidence_sources": [
|
|
{
|
|
"file": "results/auth.lan.ddnsgeek.com/scans/_patterns.log",
|
|
"match_count": 2
|
|
}
|
|
]
|
|
},
|
|
{
|
|
"host": "auth.lan.ddnsgeek.com",
|
|
"cve": "CVE-2001-0537",
|
|
"affected_host": "auth.lan.ddnsgeek.com",
|
|
"endpoint": "unknown",
|
|
"product_version_evidence": [
|
|
"http syn-ack ttl 55 Golang net/http server (Go-IPFS json-rpc or InfluxDB API)",
|
|
"http syn-ack ttl 55 Golang net/http server (Go-IPFS json-rpc or InfluxDB API)",
|
|
"http syn-ack ttl 55 Golang net/http server (Go-IPFS json-rpc or InfluxDB API)",
|
|
"ssl/http syn-ack ttl 55 Golang net/http server (Go-IPFS json-rpc or InfluxDB API)",
|
|
"ssl/http syn-ack ttl 55 Golang net/http server (Go-IPFS json-rpc or InfluxDB API)",
|
|
"tcpwrapped syn-ack ttl 56"
|
|
],
|
|
"exploit_precondition": "Validate affected product/version and exploit path prerequisites before filing.",
|
|
"reproducibility": "not-reproduced",
|
|
"disposition": "needs-manual-test",
|
|
"disposition_rationale": "Script/banner evidence exists, but no direct proof of exploit impact was captured in scan output.",
|
|
"required_reproduction_step_before_ticket": "Before creating a ticket, reproduce vulnerable behavior directly (e.g., crafted request causing data exposure, traversal read, or exploitable crash) and attach request/response proof. Banner or script signature matches alone are insufficient.",
|
|
"evidence_sources": [
|
|
{
|
|
"file": "results/auth.lan.ddnsgeek.com/scans/_patterns.log",
|
|
"match_count": 94
|
|
}
|
|
]
|
|
},
|
|
{
|
|
"host": "auth.lan.ddnsgeek.com",
|
|
"cve": "CVE-2001-0614",
|
|
"affected_host": "auth.lan.ddnsgeek.com",
|
|
"endpoint": "unknown",
|
|
"product_version_evidence": [
|
|
"http syn-ack ttl 55 Golang net/http server (Go-IPFS json-rpc or InfluxDB API)",
|
|
"http syn-ack ttl 55 Golang net/http server (Go-IPFS json-rpc or InfluxDB API)",
|
|
"http syn-ack ttl 55 Golang net/http server (Go-IPFS json-rpc or InfluxDB API)",
|
|
"ssl/http syn-ack ttl 55 Golang net/http server (Go-IPFS json-rpc or InfluxDB API)",
|
|
"ssl/http syn-ack ttl 55 Golang net/http server (Go-IPFS json-rpc or InfluxDB API)",
|
|
"tcpwrapped syn-ack ttl 56"
|
|
],
|
|
"exploit_precondition": "Validate affected product/version and exploit path prerequisites before filing.",
|
|
"reproducibility": "not-reproduced",
|
|
"disposition": "needs-manual-test",
|
|
"disposition_rationale": "Script/banner evidence exists, but no direct proof of exploit impact was captured in scan output.",
|
|
"required_reproduction_step_before_ticket": "Before creating a ticket, reproduce vulnerable behavior directly (e.g., crafted request causing data exposure, traversal read, or exploitable crash) and attach request/response proof. Banner or script signature matches alone are insufficient.",
|
|
"evidence_sources": [
|
|
{
|
|
"file": "results/auth.lan.ddnsgeek.com/scans/_patterns.log",
|
|
"match_count": 1
|
|
}
|
|
]
|
|
},
|
|
{
|
|
"host": "auth.lan.ddnsgeek.com",
|
|
"cve": "CVE-2001-0821",
|
|
"affected_host": "auth.lan.ddnsgeek.com",
|
|
"endpoint": "unknown",
|
|
"product_version_evidence": [
|
|
"http syn-ack ttl 55 Golang net/http server (Go-IPFS json-rpc or InfluxDB API)",
|
|
"http syn-ack ttl 55 Golang net/http server (Go-IPFS json-rpc or InfluxDB API)",
|
|
"http syn-ack ttl 55 Golang net/http server (Go-IPFS json-rpc or InfluxDB API)",
|
|
"ssl/http syn-ack ttl 55 Golang net/http server (Go-IPFS json-rpc or InfluxDB API)",
|
|
"ssl/http syn-ack ttl 55 Golang net/http server (Go-IPFS json-rpc or InfluxDB API)",
|
|
"tcpwrapped syn-ack ttl 56"
|
|
],
|
|
"exploit_precondition": "Validate affected product/version and exploit path prerequisites before filing.",
|
|
"reproducibility": "not-reproduced",
|
|
"disposition": "needs-manual-test",
|
|
"disposition_rationale": "Script/banner evidence exists, but no direct proof of exploit impact was captured in scan output.",
|
|
"required_reproduction_step_before_ticket": "Before creating a ticket, reproduce vulnerable behavior directly (e.g., crafted request causing data exposure, traversal read, or exploitable crash) and attach request/response proof. Banner or script signature matches alone are insufficient.",
|
|
"evidence_sources": [
|
|
{
|
|
"file": "results/auth.lan.ddnsgeek.com/scans/_patterns.log",
|
|
"match_count": 4
|
|
}
|
|
]
|
|
},
|
|
{
|
|
"host": "auth.lan.ddnsgeek.com",
|
|
"cve": "CVE-2001-0868",
|
|
"affected_host": "auth.lan.ddnsgeek.com",
|
|
"endpoint": "unknown",
|
|
"product_version_evidence": [
|
|
"http syn-ack ttl 55 Golang net/http server (Go-IPFS json-rpc or InfluxDB API)",
|
|
"http syn-ack ttl 55 Golang net/http server (Go-IPFS json-rpc or InfluxDB API)",
|
|
"http syn-ack ttl 55 Golang net/http server (Go-IPFS json-rpc or InfluxDB API)",
|
|
"ssl/http syn-ack ttl 55 Golang net/http server (Go-IPFS json-rpc or InfluxDB API)",
|
|
"ssl/http syn-ack ttl 55 Golang net/http server (Go-IPFS json-rpc or InfluxDB API)",
|
|
"tcpwrapped syn-ack ttl 56"
|
|
],
|
|
"exploit_precondition": "Validate affected product/version and exploit path prerequisites before filing.",
|
|
"reproducibility": "not-reproduced",
|
|
"disposition": "needs-manual-test",
|
|
"disposition_rationale": "Script/banner evidence exists, but no direct proof of exploit impact was captured in scan output.",
|
|
"required_reproduction_step_before_ticket": "Before creating a ticket, reproduce vulnerable behavior directly (e.g., crafted request causing data exposure, traversal read, or exploitable crash) and attach request/response proof. Banner or script signature matches alone are insufficient.",
|
|
"evidence_sources": [
|
|
{
|
|
"file": "results/auth.lan.ddnsgeek.com/scans/_patterns.log",
|
|
"match_count": 2
|
|
}
|
|
]
|
|
},
|
|
{
|
|
"host": "auth.lan.ddnsgeek.com",
|
|
"cve": "CVE-2001-1013",
|
|
"affected_host": "auth.lan.ddnsgeek.com",
|
|
"endpoint": "unknown",
|
|
"product_version_evidence": [
|
|
"http syn-ack ttl 55 Golang net/http server (Go-IPFS json-rpc or InfluxDB API)",
|
|
"http syn-ack ttl 55 Golang net/http server (Go-IPFS json-rpc or InfluxDB API)",
|
|
"http syn-ack ttl 55 Golang net/http server (Go-IPFS json-rpc or InfluxDB API)",
|
|
"ssl/http syn-ack ttl 55 Golang net/http server (Go-IPFS json-rpc or InfluxDB API)",
|
|
"ssl/http syn-ack ttl 55 Golang net/http server (Go-IPFS json-rpc or InfluxDB API)",
|
|
"tcpwrapped syn-ack ttl 56"
|
|
],
|
|
"exploit_precondition": "Validate affected product/version and exploit path prerequisites before filing.",
|
|
"reproducibility": "not-reproduced",
|
|
"disposition": "needs-manual-test",
|
|
"disposition_rationale": "Script/banner evidence exists, but no direct proof of exploit impact was captured in scan output.",
|
|
"required_reproduction_step_before_ticket": "Before creating a ticket, reproduce vulnerable behavior directly (e.g., crafted request causing data exposure, traversal read, or exploitable crash) and attach request/response proof. Banner or script signature matches alone are insufficient.",
|
|
"evidence_sources": [
|
|
{
|
|
"file": "results/auth.lan.ddnsgeek.com/scans/_patterns.log",
|
|
"match_count": 1
|
|
}
|
|
]
|
|
},
|
|
{
|
|
"host": "auth.lan.ddnsgeek.com",
|
|
"cve": "CVE-2001-1151",
|
|
"affected_host": "auth.lan.ddnsgeek.com",
|
|
"endpoint": "unknown",
|
|
"product_version_evidence": [
|
|
"http syn-ack ttl 55 Golang net/http server (Go-IPFS json-rpc or InfluxDB API)",
|
|
"http syn-ack ttl 55 Golang net/http server (Go-IPFS json-rpc or InfluxDB API)",
|
|
"http syn-ack ttl 55 Golang net/http server (Go-IPFS json-rpc or InfluxDB API)",
|
|
"ssl/http syn-ack ttl 55 Golang net/http server (Go-IPFS json-rpc or InfluxDB API)",
|
|
"ssl/http syn-ack ttl 55 Golang net/http server (Go-IPFS json-rpc or InfluxDB API)",
|
|
"tcpwrapped syn-ack ttl 56"
|
|
],
|
|
"exploit_precondition": "Validate affected product/version and exploit path prerequisites before filing.",
|
|
"reproducibility": "not-reproduced",
|
|
"disposition": "needs-manual-test",
|
|
"disposition_rationale": "Script/banner evidence exists, but no direct proof of exploit impact was captured in scan output.",
|
|
"required_reproduction_step_before_ticket": "Before creating a ticket, reproduce vulnerable behavior directly (e.g., crafted request causing data exposure, traversal read, or exploitable crash) and attach request/response proof. Banner or script signature matches alone are insufficient.",
|
|
"evidence_sources": [
|
|
{
|
|
"file": "results/auth.lan.ddnsgeek.com/scans/_patterns.log",
|
|
"match_count": 1
|
|
}
|
|
]
|
|
},
|
|
{
|
|
"host": "auth.lan.ddnsgeek.com",
|
|
"cve": "CVE-2001-1198",
|
|
"affected_host": "auth.lan.ddnsgeek.com",
|
|
"endpoint": "unknown",
|
|
"product_version_evidence": [
|
|
"http syn-ack ttl 55 Golang net/http server (Go-IPFS json-rpc or InfluxDB API)",
|
|
"http syn-ack ttl 55 Golang net/http server (Go-IPFS json-rpc or InfluxDB API)",
|
|
"http syn-ack ttl 55 Golang net/http server (Go-IPFS json-rpc or InfluxDB API)",
|
|
"ssl/http syn-ack ttl 55 Golang net/http server (Go-IPFS json-rpc or InfluxDB API)",
|
|
"ssl/http syn-ack ttl 55 Golang net/http server (Go-IPFS json-rpc or InfluxDB API)",
|
|
"tcpwrapped syn-ack ttl 56"
|
|
],
|
|
"exploit_precondition": "Validate affected product/version and exploit path prerequisites before filing.",
|
|
"reproducibility": "not-reproduced",
|
|
"disposition": "needs-manual-test",
|
|
"disposition_rationale": "Script/banner evidence exists, but no direct proof of exploit impact was captured in scan output.",
|
|
"required_reproduction_step_before_ticket": "Before creating a ticket, reproduce vulnerable behavior directly (e.g., crafted request causing data exposure, traversal read, or exploitable crash) and attach request/response proof. Banner or script signature matches alone are insufficient.",
|
|
"evidence_sources": [
|
|
{
|
|
"file": "results/auth.lan.ddnsgeek.com/scans/_patterns.log",
|
|
"match_count": 2
|
|
}
|
|
]
|
|
},
|
|
{
|
|
"host": "auth.lan.ddnsgeek.com",
|
|
"cve": "CVE-2001-1586",
|
|
"affected_host": "auth.lan.ddnsgeek.com",
|
|
"endpoint": "unknown",
|
|
"product_version_evidence": [
|
|
"http syn-ack ttl 55 Golang net/http server (Go-IPFS json-rpc or InfluxDB API)",
|
|
"http syn-ack ttl 55 Golang net/http server (Go-IPFS json-rpc or InfluxDB API)",
|
|
"http syn-ack ttl 55 Golang net/http server (Go-IPFS json-rpc or InfluxDB API)",
|
|
"ssl/http syn-ack ttl 55 Golang net/http server (Go-IPFS json-rpc or InfluxDB API)",
|
|
"ssl/http syn-ack ttl 55 Golang net/http server (Go-IPFS json-rpc or InfluxDB API)",
|
|
"tcpwrapped syn-ack ttl 56"
|
|
],
|
|
"exploit_precondition": "Validate affected product/version and exploit path prerequisites before filing.",
|
|
"reproducibility": "not-reproduced",
|
|
"disposition": "needs-manual-test",
|
|
"disposition_rationale": "Script/banner evidence exists, but no direct proof of exploit impact was captured in scan output.",
|
|
"required_reproduction_step_before_ticket": "Before creating a ticket, reproduce vulnerable behavior directly (e.g., crafted request causing data exposure, traversal read, or exploitable crash) and attach request/response proof. Banner or script signature matches alone are insufficient.",
|
|
"evidence_sources": [
|
|
{
|
|
"file": "results/auth.lan.ddnsgeek.com/scans/_patterns.log",
|
|
"match_count": 1
|
|
}
|
|
]
|
|
},
|
|
{
|
|
"host": "auth.lan.ddnsgeek.com",
|
|
"cve": "CVE-2002-0095",
|
|
"affected_host": "auth.lan.ddnsgeek.com",
|
|
"endpoint": "unknown",
|
|
"product_version_evidence": [
|
|
"http syn-ack ttl 55 Golang net/http server (Go-IPFS json-rpc or InfluxDB API)",
|
|
"http syn-ack ttl 55 Golang net/http server (Go-IPFS json-rpc or InfluxDB API)",
|
|
"http syn-ack ttl 55 Golang net/http server (Go-IPFS json-rpc or InfluxDB API)",
|
|
"ssl/http syn-ack ttl 55 Golang net/http server (Go-IPFS json-rpc or InfluxDB API)",
|
|
"ssl/http syn-ack ttl 55 Golang net/http server (Go-IPFS json-rpc or InfluxDB API)",
|
|
"tcpwrapped syn-ack ttl 56"
|
|
],
|
|
"exploit_precondition": "Validate affected product/version and exploit path prerequisites before filing.",
|
|
"reproducibility": "not-reproduced",
|
|
"disposition": "needs-manual-test",
|
|
"disposition_rationale": "Script/banner evidence exists, but no direct proof of exploit impact was captured in scan output.",
|
|
"required_reproduction_step_before_ticket": "Before creating a ticket, reproduce vulnerable behavior directly (e.g., crafted request causing data exposure, traversal read, or exploitable crash) and attach request/response proof. Banner or script signature matches alone are insufficient.",
|
|
"evidence_sources": [
|
|
{
|
|
"file": "results/auth.lan.ddnsgeek.com/scans/_patterns.log",
|
|
"match_count": 1
|
|
}
|
|
]
|
|
},
|
|
{
|
|
"host": "auth.lan.ddnsgeek.com",
|
|
"cve": "CVE-2002-0128",
|
|
"affected_host": "auth.lan.ddnsgeek.com",
|
|
"endpoint": "unknown",
|
|
"product_version_evidence": [
|
|
"http syn-ack ttl 55 Golang net/http server (Go-IPFS json-rpc or InfluxDB API)",
|
|
"http syn-ack ttl 55 Golang net/http server (Go-IPFS json-rpc or InfluxDB API)",
|
|
"http syn-ack ttl 55 Golang net/http server (Go-IPFS json-rpc or InfluxDB API)",
|
|
"ssl/http syn-ack ttl 55 Golang net/http server (Go-IPFS json-rpc or InfluxDB API)",
|
|
"ssl/http syn-ack ttl 55 Golang net/http server (Go-IPFS json-rpc or InfluxDB API)",
|
|
"tcpwrapped syn-ack ttl 56"
|
|
],
|
|
"exploit_precondition": "Validate affected product/version and exploit path prerequisites before filing.",
|
|
"reproducibility": "not-reproduced",
|
|
"disposition": "needs-manual-test",
|
|
"disposition_rationale": "Script/banner evidence exists, but no direct proof of exploit impact was captured in scan output.",
|
|
"required_reproduction_step_before_ticket": "Before creating a ticket, reproduce vulnerable behavior directly (e.g., crafted request causing data exposure, traversal read, or exploitable crash) and attach request/response proof. Banner or script signature matches alone are insufficient.",
|
|
"evidence_sources": [
|
|
{
|
|
"file": "results/auth.lan.ddnsgeek.com/scans/_patterns.log",
|
|
"match_count": 1
|
|
}
|
|
]
|
|
},
|
|
{
|
|
"host": "auth.lan.ddnsgeek.com",
|
|
"cve": "CVE-2002-0220",
|
|
"affected_host": "auth.lan.ddnsgeek.com",
|
|
"endpoint": "unknown",
|
|
"product_version_evidence": [
|
|
"http syn-ack ttl 55 Golang net/http server (Go-IPFS json-rpc or InfluxDB API)",
|
|
"http syn-ack ttl 55 Golang net/http server (Go-IPFS json-rpc or InfluxDB API)",
|
|
"http syn-ack ttl 55 Golang net/http server (Go-IPFS json-rpc or InfluxDB API)",
|
|
"ssl/http syn-ack ttl 55 Golang net/http server (Go-IPFS json-rpc or InfluxDB API)",
|
|
"ssl/http syn-ack ttl 55 Golang net/http server (Go-IPFS json-rpc or InfluxDB API)",
|
|
"tcpwrapped syn-ack ttl 56"
|
|
],
|
|
"exploit_precondition": "Validate affected product/version and exploit path prerequisites before filing.",
|
|
"reproducibility": "not-reproduced",
|
|
"disposition": "needs-manual-test",
|
|
"disposition_rationale": "Script/banner evidence exists, but no direct proof of exploit impact was captured in scan output.",
|
|
"required_reproduction_step_before_ticket": "Before creating a ticket, reproduce vulnerable behavior directly (e.g., crafted request causing data exposure, traversal read, or exploitable crash) and attach request/response proof. Banner or script signature matches alone are insufficient.",
|
|
"evidence_sources": [
|
|
{
|
|
"file": "results/auth.lan.ddnsgeek.com/scans/_patterns.log",
|
|
"match_count": 1
|
|
}
|
|
]
|
|
},
|
|
{
|
|
"host": "auth.lan.ddnsgeek.com",
|
|
"cve": "CVE-2002-0301",
|
|
"affected_host": "auth.lan.ddnsgeek.com",
|
|
"endpoint": "unknown",
|
|
"product_version_evidence": [
|
|
"http syn-ack ttl 55 Golang net/http server (Go-IPFS json-rpc or InfluxDB API)",
|
|
"http syn-ack ttl 55 Golang net/http server (Go-IPFS json-rpc or InfluxDB API)",
|
|
"http syn-ack ttl 55 Golang net/http server (Go-IPFS json-rpc or InfluxDB API)",
|
|
"ssl/http syn-ack ttl 55 Golang net/http server (Go-IPFS json-rpc or InfluxDB API)",
|
|
"ssl/http syn-ack ttl 55 Golang net/http server (Go-IPFS json-rpc or InfluxDB API)",
|
|
"tcpwrapped syn-ack ttl 56"
|
|
],
|
|
"exploit_precondition": "Validate affected product/version and exploit path prerequisites before filing.",
|
|
"reproducibility": "not-reproduced",
|
|
"disposition": "needs-manual-test",
|
|
"disposition_rationale": "Script/banner evidence exists, but no direct proof of exploit impact was captured in scan output.",
|
|
"required_reproduction_step_before_ticket": "Before creating a ticket, reproduce vulnerable behavior directly (e.g., crafted request causing data exposure, traversal read, or exploitable crash) and attach request/response proof. Banner or script signature matches alone are insufficient.",
|
|
"evidence_sources": [
|
|
{
|
|
"file": "results/auth.lan.ddnsgeek.com/scans/_patterns.log",
|
|
"match_count": 1
|
|
}
|
|
]
|
|
},
|
|
{
|
|
"host": "auth.lan.ddnsgeek.com",
|
|
"cve": "CVE-2002-0308",
|
|
"affected_host": "auth.lan.ddnsgeek.com",
|
|
"endpoint": "unknown",
|
|
"product_version_evidence": [
|
|
"http syn-ack ttl 55 Golang net/http server (Go-IPFS json-rpc or InfluxDB API)",
|
|
"http syn-ack ttl 55 Golang net/http server (Go-IPFS json-rpc or InfluxDB API)",
|
|
"http syn-ack ttl 55 Golang net/http server (Go-IPFS json-rpc or InfluxDB API)",
|
|
"ssl/http syn-ack ttl 55 Golang net/http server (Go-IPFS json-rpc or InfluxDB API)",
|
|
"ssl/http syn-ack ttl 55 Golang net/http server (Go-IPFS json-rpc or InfluxDB API)",
|
|
"tcpwrapped syn-ack ttl 56"
|
|
],
|
|
"exploit_precondition": "Validate affected product/version and exploit path prerequisites before filing.",
|
|
"reproducibility": "not-reproduced",
|
|
"disposition": "needs-manual-test",
|
|
"disposition_rationale": "Script/banner evidence exists, but no direct proof of exploit impact was captured in scan output.",
|
|
"required_reproduction_step_before_ticket": "Before creating a ticket, reproduce vulnerable behavior directly (e.g., crafted request causing data exposure, traversal read, or exploitable crash) and attach request/response proof. Banner or script signature matches alone are insufficient.",
|
|
"evidence_sources": [
|
|
{
|
|
"file": "results/auth.lan.ddnsgeek.com/scans/_patterns.log",
|
|
"match_count": 1
|
|
}
|
|
]
|
|
},
|
|
{
|
|
"host": "auth.lan.ddnsgeek.com",
|
|
"cve": "CVE-2002-0325",
|
|
"affected_host": "auth.lan.ddnsgeek.com",
|
|
"endpoint": "unknown",
|
|
"product_version_evidence": [
|
|
"http syn-ack ttl 55 Golang net/http server (Go-IPFS json-rpc or InfluxDB API)",
|
|
"http syn-ack ttl 55 Golang net/http server (Go-IPFS json-rpc or InfluxDB API)",
|
|
"http syn-ack ttl 55 Golang net/http server (Go-IPFS json-rpc or InfluxDB API)",
|
|
"ssl/http syn-ack ttl 55 Golang net/http server (Go-IPFS json-rpc or InfluxDB API)",
|
|
"ssl/http syn-ack ttl 55 Golang net/http server (Go-IPFS json-rpc or InfluxDB API)",
|
|
"tcpwrapped syn-ack ttl 56"
|
|
],
|
|
"exploit_precondition": "Validate affected product/version and exploit path prerequisites before filing.",
|
|
"reproducibility": "not-reproduced",
|
|
"disposition": "needs-manual-test",
|
|
"disposition_rationale": "Script/banner evidence exists, but no direct proof of exploit impact was captured in scan output.",
|
|
"required_reproduction_step_before_ticket": "Before creating a ticket, reproduce vulnerable behavior directly (e.g., crafted request causing data exposure, traversal read, or exploitable crash) and attach request/response proof. Banner or script signature matches alone are insufficient.",
|
|
"evidence_sources": [
|
|
{
|
|
"file": "results/auth.lan.ddnsgeek.com/scans/_patterns.log",
|
|
"match_count": 9
|
|
}
|
|
]
|
|
},
|
|
{
|
|
"host": "auth.lan.ddnsgeek.com",
|
|
"cve": "CVE-2002-0385",
|
|
"affected_host": "auth.lan.ddnsgeek.com",
|
|
"endpoint": "unknown",
|
|
"product_version_evidence": [
|
|
"http syn-ack ttl 55 Golang net/http server (Go-IPFS json-rpc or InfluxDB API)",
|
|
"http syn-ack ttl 55 Golang net/http server (Go-IPFS json-rpc or InfluxDB API)",
|
|
"http syn-ack ttl 55 Golang net/http server (Go-IPFS json-rpc or InfluxDB API)",
|
|
"ssl/http syn-ack ttl 55 Golang net/http server (Go-IPFS json-rpc or InfluxDB API)",
|
|
"ssl/http syn-ack ttl 55 Golang net/http server (Go-IPFS json-rpc or InfluxDB API)",
|
|
"tcpwrapped syn-ack ttl 56"
|
|
],
|
|
"exploit_precondition": "Validate affected product/version and exploit path prerequisites before filing.",
|
|
"reproducibility": "not-reproduced",
|
|
"disposition": "needs-manual-test",
|
|
"disposition_rationale": "Script/banner evidence exists, but no direct proof of exploit impact was captured in scan output.",
|
|
"required_reproduction_step_before_ticket": "Before creating a ticket, reproduce vulnerable behavior directly (e.g., crafted request causing data exposure, traversal read, or exploitable crash) and attach request/response proof. Banner or script signature matches alone are insufficient.",
|
|
"evidence_sources": [
|
|
{
|
|
"file": "results/auth.lan.ddnsgeek.com/scans/_patterns.log",
|
|
"match_count": 1
|
|
}
|
|
]
|
|
},
|
|
{
|
|
"host": "auth.lan.ddnsgeek.com",
|
|
"cve": "CVE-2002-0436",
|
|
"affected_host": "auth.lan.ddnsgeek.com",
|
|
"endpoint": "unknown",
|
|
"product_version_evidence": [
|
|
"http syn-ack ttl 55 Golang net/http server (Go-IPFS json-rpc or InfluxDB API)",
|
|
"http syn-ack ttl 55 Golang net/http server (Go-IPFS json-rpc or InfluxDB API)",
|
|
"http syn-ack ttl 55 Golang net/http server (Go-IPFS json-rpc or InfluxDB API)",
|
|
"ssl/http syn-ack ttl 55 Golang net/http server (Go-IPFS json-rpc or InfluxDB API)",
|
|
"ssl/http syn-ack ttl 55 Golang net/http server (Go-IPFS json-rpc or InfluxDB API)",
|
|
"tcpwrapped syn-ack ttl 56"
|
|
],
|
|
"exploit_precondition": "Validate affected product/version and exploit path prerequisites before filing.",
|
|
"reproducibility": "not-reproduced",
|
|
"disposition": "needs-manual-test",
|
|
"disposition_rationale": "Script/banner evidence exists, but no direct proof of exploit impact was captured in scan output.",
|
|
"required_reproduction_step_before_ticket": "Before creating a ticket, reproduce vulnerable behavior directly (e.g., crafted request causing data exposure, traversal read, or exploitable crash) and attach request/response proof. Banner or script signature matches alone are insufficient.",
|
|
"evidence_sources": [
|
|
{
|
|
"file": "results/auth.lan.ddnsgeek.com/scans/_patterns.log",
|
|
"match_count": 1
|
|
}
|
|
]
|
|
},
|
|
{
|
|
"host": "auth.lan.ddnsgeek.com",
|
|
"cve": "CVE-2002-0490",
|
|
"affected_host": "auth.lan.ddnsgeek.com",
|
|
"endpoint": "unknown",
|
|
"product_version_evidence": [
|
|
"http syn-ack ttl 55 Golang net/http server (Go-IPFS json-rpc or InfluxDB API)",
|
|
"http syn-ack ttl 55 Golang net/http server (Go-IPFS json-rpc or InfluxDB API)",
|
|
"http syn-ack ttl 55 Golang net/http server (Go-IPFS json-rpc or InfluxDB API)",
|
|
"ssl/http syn-ack ttl 55 Golang net/http server (Go-IPFS json-rpc or InfluxDB API)",
|
|
"ssl/http syn-ack ttl 55 Golang net/http server (Go-IPFS json-rpc or InfluxDB API)",
|
|
"tcpwrapped syn-ack ttl 56"
|
|
],
|
|
"exploit_precondition": "Validate affected product/version and exploit path prerequisites before filing.",
|
|
"reproducibility": "not-reproduced",
|
|
"disposition": "needs-manual-test",
|
|
"disposition_rationale": "Script/banner evidence exists, but no direct proof of exploit impact was captured in scan output.",
|
|
"required_reproduction_step_before_ticket": "Before creating a ticket, reproduce vulnerable behavior directly (e.g., crafted request causing data exposure, traversal read, or exploitable crash) and attach request/response proof. Banner or script signature matches alone are insufficient.",
|
|
"evidence_sources": [
|
|
{
|
|
"file": "results/auth.lan.ddnsgeek.com/scans/_patterns.log",
|
|
"match_count": 1
|
|
}
|
|
]
|
|
},
|
|
{
|
|
"host": "auth.lan.ddnsgeek.com",
|
|
"cve": "CVE-2002-0502",
|
|
"affected_host": "auth.lan.ddnsgeek.com",
|
|
"endpoint": "unknown",
|
|
"product_version_evidence": [
|
|
"http syn-ack ttl 55 Golang net/http server (Go-IPFS json-rpc or InfluxDB API)",
|
|
"http syn-ack ttl 55 Golang net/http server (Go-IPFS json-rpc or InfluxDB API)",
|
|
"http syn-ack ttl 55 Golang net/http server (Go-IPFS json-rpc or InfluxDB API)",
|
|
"ssl/http syn-ack ttl 55 Golang net/http server (Go-IPFS json-rpc or InfluxDB API)",
|
|
"ssl/http syn-ack ttl 55 Golang net/http server (Go-IPFS json-rpc or InfluxDB API)",
|
|
"tcpwrapped syn-ack ttl 56"
|
|
],
|
|
"exploit_precondition": "Validate affected product/version and exploit path prerequisites before filing.",
|
|
"reproducibility": "not-reproduced",
|
|
"disposition": "needs-manual-test",
|
|
"disposition_rationale": "Script/banner evidence exists, but no direct proof of exploit impact was captured in scan output.",
|
|
"required_reproduction_step_before_ticket": "Before creating a ticket, reproduce vulnerable behavior directly (e.g., crafted request causing data exposure, traversal read, or exploitable crash) and attach request/response proof. Banner or script signature matches alone are insufficient.",
|
|
"evidence_sources": [
|
|
{
|
|
"file": "results/auth.lan.ddnsgeek.com/scans/_patterns.log",
|
|
"match_count": 1
|
|
}
|
|
]
|
|
},
|
|
{
|
|
"host": "auth.lan.ddnsgeek.com",
|
|
"cve": "CVE-2002-0562",
|
|
"affected_host": "auth.lan.ddnsgeek.com",
|
|
"endpoint": "unknown",
|
|
"product_version_evidence": [
|
|
"http syn-ack ttl 55 Golang net/http server (Go-IPFS json-rpc or InfluxDB API)",
|
|
"http syn-ack ttl 55 Golang net/http server (Go-IPFS json-rpc or InfluxDB API)",
|
|
"http syn-ack ttl 55 Golang net/http server (Go-IPFS json-rpc or InfluxDB API)",
|
|
"ssl/http syn-ack ttl 55 Golang net/http server (Go-IPFS json-rpc or InfluxDB API)",
|
|
"ssl/http syn-ack ttl 55 Golang net/http server (Go-IPFS json-rpc or InfluxDB API)",
|
|
"tcpwrapped syn-ack ttl 56"
|
|
],
|
|
"exploit_precondition": "Validate affected product/version and exploit path prerequisites before filing.",
|
|
"reproducibility": "not-reproduced",
|
|
"disposition": "needs-manual-test",
|
|
"disposition_rationale": "Script/banner evidence exists, but no direct proof of exploit impact was captured in scan output.",
|
|
"required_reproduction_step_before_ticket": "Before creating a ticket, reproduce vulnerable behavior directly (e.g., crafted request causing data exposure, traversal read, or exploitable crash) and attach request/response proof. Banner or script signature matches alone are insufficient.",
|
|
"evidence_sources": [
|
|
{
|
|
"file": "results/auth.lan.ddnsgeek.com/scans/_patterns.log",
|
|
"match_count": 1
|
|
}
|
|
]
|
|
},
|
|
{
|
|
"host": "auth.lan.ddnsgeek.com",
|
|
"cve": "CVE-2002-0568",
|
|
"affected_host": "auth.lan.ddnsgeek.com",
|
|
"endpoint": "unknown",
|
|
"product_version_evidence": [
|
|
"http syn-ack ttl 55 Golang net/http server (Go-IPFS json-rpc or InfluxDB API)",
|
|
"http syn-ack ttl 55 Golang net/http server (Go-IPFS json-rpc or InfluxDB API)",
|
|
"http syn-ack ttl 55 Golang net/http server (Go-IPFS json-rpc or InfluxDB API)",
|
|
"ssl/http syn-ack ttl 55 Golang net/http server (Go-IPFS json-rpc or InfluxDB API)",
|
|
"ssl/http syn-ack ttl 55 Golang net/http server (Go-IPFS json-rpc or InfluxDB API)",
|
|
"tcpwrapped syn-ack ttl 56"
|
|
],
|
|
"exploit_precondition": "Validate affected product/version and exploit path prerequisites before filing.",
|
|
"reproducibility": "not-reproduced",
|
|
"disposition": "needs-manual-test",
|
|
"disposition_rationale": "Script/banner evidence exists, but no direct proof of exploit impact was captured in scan output.",
|
|
"required_reproduction_step_before_ticket": "Before creating a ticket, reproduce vulnerable behavior directly (e.g., crafted request causing data exposure, traversal read, or exploitable crash) and attach request/response proof. Banner or script signature matches alone are insufficient.",
|
|
"evidence_sources": [
|
|
{
|
|
"file": "results/auth.lan.ddnsgeek.com/scans/_patterns.log",
|
|
"match_count": 2
|
|
}
|
|
]
|
|
},
|
|
{
|
|
"host": "auth.lan.ddnsgeek.com",
|
|
"cve": "CVE-2002-0579",
|
|
"affected_host": "auth.lan.ddnsgeek.com",
|
|
"endpoint": "unknown",
|
|
"product_version_evidence": [
|
|
"http syn-ack ttl 55 Golang net/http server (Go-IPFS json-rpc or InfluxDB API)",
|
|
"http syn-ack ttl 55 Golang net/http server (Go-IPFS json-rpc or InfluxDB API)",
|
|
"http syn-ack ttl 55 Golang net/http server (Go-IPFS json-rpc or InfluxDB API)",
|
|
"ssl/http syn-ack ttl 55 Golang net/http server (Go-IPFS json-rpc or InfluxDB API)",
|
|
"ssl/http syn-ack ttl 55 Golang net/http server (Go-IPFS json-rpc or InfluxDB API)",
|
|
"tcpwrapped syn-ack ttl 56"
|
|
],
|
|
"exploit_precondition": "Validate affected product/version and exploit path prerequisites before filing.",
|
|
"reproducibility": "not-reproduced",
|
|
"disposition": "needs-manual-test",
|
|
"disposition_rationale": "Script/banner evidence exists, but no direct proof of exploit impact was captured in scan output.",
|
|
"required_reproduction_step_before_ticket": "Before creating a ticket, reproduce vulnerable behavior directly (e.g., crafted request causing data exposure, traversal read, or exploitable crash) and attach request/response proof. Banner or script signature matches alone are insufficient.",
|
|
"evidence_sources": [
|
|
{
|
|
"file": "results/auth.lan.ddnsgeek.com/scans/_patterns.log",
|
|
"match_count": 3
|
|
}
|
|
]
|
|
},
|
|
{
|
|
"host": "auth.lan.ddnsgeek.com",
|
|
"cve": "CVE-2002-0599",
|
|
"affected_host": "auth.lan.ddnsgeek.com",
|
|
"endpoint": "unknown",
|
|
"product_version_evidence": [
|
|
"http syn-ack ttl 55 Golang net/http server (Go-IPFS json-rpc or InfluxDB API)",
|
|
"http syn-ack ttl 55 Golang net/http server (Go-IPFS json-rpc or InfluxDB API)",
|
|
"http syn-ack ttl 55 Golang net/http server (Go-IPFS json-rpc or InfluxDB API)",
|
|
"ssl/http syn-ack ttl 55 Golang net/http server (Go-IPFS json-rpc or InfluxDB API)",
|
|
"ssl/http syn-ack ttl 55 Golang net/http server (Go-IPFS json-rpc or InfluxDB API)",
|
|
"tcpwrapped syn-ack ttl 56"
|
|
],
|
|
"exploit_precondition": "Validate affected product/version and exploit path prerequisites before filing.",
|
|
"reproducibility": "not-reproduced",
|
|
"disposition": "needs-manual-test",
|
|
"disposition_rationale": "Script/banner evidence exists, but no direct proof of exploit impact was captured in scan output.",
|
|
"required_reproduction_step_before_ticket": "Before creating a ticket, reproduce vulnerable behavior directly (e.g., crafted request causing data exposure, traversal read, or exploitable crash) and attach request/response proof. Banner or script signature matches alone are insufficient.",
|
|
"evidence_sources": [
|
|
{
|
|
"file": "results/auth.lan.ddnsgeek.com/scans/_patterns.log",
|
|
"match_count": 1
|
|
}
|
|
]
|
|
},
|
|
{
|
|
"host": "auth.lan.ddnsgeek.com",
|
|
"cve": "CVE-2002-0614",
|
|
"affected_host": "auth.lan.ddnsgeek.com",
|
|
"endpoint": "unknown",
|
|
"product_version_evidence": [
|
|
"http syn-ack ttl 55 Golang net/http server (Go-IPFS json-rpc or InfluxDB API)",
|
|
"http syn-ack ttl 55 Golang net/http server (Go-IPFS json-rpc or InfluxDB API)",
|
|
"http syn-ack ttl 55 Golang net/http server (Go-IPFS json-rpc or InfluxDB API)",
|
|
"ssl/http syn-ack ttl 55 Golang net/http server (Go-IPFS json-rpc or InfluxDB API)",
|
|
"ssl/http syn-ack ttl 55 Golang net/http server (Go-IPFS json-rpc or InfluxDB API)",
|
|
"tcpwrapped syn-ack ttl 56"
|
|
],
|
|
"exploit_precondition": "Validate affected product/version and exploit path prerequisites before filing.",
|
|
"reproducibility": "not-reproduced",
|
|
"disposition": "needs-manual-test",
|
|
"disposition_rationale": "Script/banner evidence exists, but no direct proof of exploit impact was captured in scan output.",
|
|
"required_reproduction_step_before_ticket": "Before creating a ticket, reproduce vulnerable behavior directly (e.g., crafted request causing data exposure, traversal read, or exploitable crash) and attach request/response proof. Banner or script signature matches alone are insufficient.",
|
|
"evidence_sources": [
|
|
{
|
|
"file": "results/auth.lan.ddnsgeek.com/scans/_patterns.log",
|
|
"match_count": 1
|
|
}
|
|
]
|
|
},
|
|
{
|
|
"host": "auth.lan.ddnsgeek.com",
|
|
"cve": "CVE-2002-0705",
|
|
"affected_host": "auth.lan.ddnsgeek.com",
|
|
"endpoint": "unknown",
|
|
"product_version_evidence": [
|
|
"http syn-ack ttl 55 Golang net/http server (Go-IPFS json-rpc or InfluxDB API)",
|
|
"http syn-ack ttl 55 Golang net/http server (Go-IPFS json-rpc or InfluxDB API)",
|
|
"http syn-ack ttl 55 Golang net/http server (Go-IPFS json-rpc or InfluxDB API)",
|
|
"ssl/http syn-ack ttl 55 Golang net/http server (Go-IPFS json-rpc or InfluxDB API)",
|
|
"ssl/http syn-ack ttl 55 Golang net/http server (Go-IPFS json-rpc or InfluxDB API)",
|
|
"tcpwrapped syn-ack ttl 56"
|
|
],
|
|
"exploit_precondition": "Validate affected product/version and exploit path prerequisites before filing.",
|
|
"reproducibility": "not-reproduced",
|
|
"disposition": "needs-manual-test",
|
|
"disposition_rationale": "Script/banner evidence exists, but no direct proof of exploit impact was captured in scan output.",
|
|
"required_reproduction_step_before_ticket": "Before creating a ticket, reproduce vulnerable behavior directly (e.g., crafted request causing data exposure, traversal read, or exploitable crash) and attach request/response proof. Banner or script signature matches alone are insufficient.",
|
|
"evidence_sources": [
|
|
{
|
|
"file": "results/auth.lan.ddnsgeek.com/scans/_patterns.log",
|
|
"match_count": 1
|
|
}
|
|
]
|
|
},
|
|
{
|
|
"host": "auth.lan.ddnsgeek.com",
|
|
"cve": "CVE-2002-0776",
|
|
"affected_host": "auth.lan.ddnsgeek.com",
|
|
"endpoint": "unknown",
|
|
"product_version_evidence": [
|
|
"http syn-ack ttl 55 Golang net/http server (Go-IPFS json-rpc or InfluxDB API)",
|
|
"http syn-ack ttl 55 Golang net/http server (Go-IPFS json-rpc or InfluxDB API)",
|
|
"http syn-ack ttl 55 Golang net/http server (Go-IPFS json-rpc or InfluxDB API)",
|
|
"ssl/http syn-ack ttl 55 Golang net/http server (Go-IPFS json-rpc or InfluxDB API)",
|
|
"ssl/http syn-ack ttl 55 Golang net/http server (Go-IPFS json-rpc or InfluxDB API)",
|
|
"tcpwrapped syn-ack ttl 56"
|
|
],
|
|
"exploit_precondition": "Validate affected product/version and exploit path prerequisites before filing.",
|
|
"reproducibility": "not-reproduced",
|
|
"disposition": "needs-manual-test",
|
|
"disposition_rationale": "Script/banner evidence exists, but no direct proof of exploit impact was captured in scan output.",
|
|
"required_reproduction_step_before_ticket": "Before creating a ticket, reproduce vulnerable behavior directly (e.g., crafted request causing data exposure, traversal read, or exploitable crash) and attach request/response proof. Banner or script signature matches alone are insufficient.",
|
|
"evidence_sources": [
|
|
{
|
|
"file": "results/auth.lan.ddnsgeek.com/scans/_patterns.log",
|
|
"match_count": 1
|
|
}
|
|
]
|
|
},
|
|
{
|
|
"host": "auth.lan.ddnsgeek.com",
|
|
"cve": "CVE-2002-0943",
|
|
"affected_host": "auth.lan.ddnsgeek.com",
|
|
"endpoint": "unknown",
|
|
"product_version_evidence": [
|
|
"http syn-ack ttl 55 Golang net/http server (Go-IPFS json-rpc or InfluxDB API)",
|
|
"http syn-ack ttl 55 Golang net/http server (Go-IPFS json-rpc or InfluxDB API)",
|
|
"http syn-ack ttl 55 Golang net/http server (Go-IPFS json-rpc or InfluxDB API)",
|
|
"ssl/http syn-ack ttl 55 Golang net/http server (Go-IPFS json-rpc or InfluxDB API)",
|
|
"ssl/http syn-ack ttl 55 Golang net/http server (Go-IPFS json-rpc or InfluxDB API)",
|
|
"tcpwrapped syn-ack ttl 56"
|
|
],
|
|
"exploit_precondition": "Validate affected product/version and exploit path prerequisites before filing.",
|
|
"reproducibility": "not-reproduced",
|
|
"disposition": "needs-manual-test",
|
|
"disposition_rationale": "Script/banner evidence exists, but no direct proof of exploit impact was captured in scan output.",
|
|
"required_reproduction_step_before_ticket": "Before creating a ticket, reproduce vulnerable behavior directly (e.g., crafted request causing data exposure, traversal read, or exploitable crash) and attach request/response proof. Banner or script signature matches alone are insufficient.",
|
|
"evidence_sources": [
|
|
{
|
|
"file": "results/auth.lan.ddnsgeek.com/scans/_patterns.log",
|
|
"match_count": 7
|
|
}
|
|
]
|
|
},
|
|
{
|
|
"host": "auth.lan.ddnsgeek.com",
|
|
"cve": "CVE-2002-0995",
|
|
"affected_host": "auth.lan.ddnsgeek.com",
|
|
"endpoint": "unknown",
|
|
"product_version_evidence": [
|
|
"http syn-ack ttl 55 Golang net/http server (Go-IPFS json-rpc or InfluxDB API)",
|
|
"http syn-ack ttl 55 Golang net/http server (Go-IPFS json-rpc or InfluxDB API)",
|
|
"http syn-ack ttl 55 Golang net/http server (Go-IPFS json-rpc or InfluxDB API)",
|
|
"ssl/http syn-ack ttl 55 Golang net/http server (Go-IPFS json-rpc or InfluxDB API)",
|
|
"ssl/http syn-ack ttl 55 Golang net/http server (Go-IPFS json-rpc or InfluxDB API)",
|
|
"tcpwrapped syn-ack ttl 56"
|
|
],
|
|
"exploit_precondition": "Validate affected product/version and exploit path prerequisites before filing.",
|
|
"reproducibility": "not-reproduced",
|
|
"disposition": "needs-manual-test",
|
|
"disposition_rationale": "Script/banner evidence exists, but no direct proof of exploit impact was captured in scan output.",
|
|
"required_reproduction_step_before_ticket": "Before creating a ticket, reproduce vulnerable behavior directly (e.g., crafted request causing data exposure, traversal read, or exploitable crash) and attach request/response proof. Banner or script signature matches alone are insufficient.",
|
|
"evidence_sources": [
|
|
{
|
|
"file": "results/auth.lan.ddnsgeek.com/scans/_patterns.log",
|
|
"match_count": 1
|
|
}
|
|
]
|
|
},
|
|
{
|
|
"host": "auth.lan.ddnsgeek.com",
|
|
"cve": "CVE-2002-1081",
|
|
"affected_host": "auth.lan.ddnsgeek.com",
|
|
"endpoint": "unknown",
|
|
"product_version_evidence": [
|
|
"http syn-ack ttl 55 Golang net/http server (Go-IPFS json-rpc or InfluxDB API)",
|
|
"http syn-ack ttl 55 Golang net/http server (Go-IPFS json-rpc or InfluxDB API)",
|
|
"http syn-ack ttl 55 Golang net/http server (Go-IPFS json-rpc or InfluxDB API)",
|
|
"ssl/http syn-ack ttl 55 Golang net/http server (Go-IPFS json-rpc or InfluxDB API)",
|
|
"ssl/http syn-ack ttl 55 Golang net/http server (Go-IPFS json-rpc or InfluxDB API)",
|
|
"tcpwrapped syn-ack ttl 56"
|
|
],
|
|
"exploit_precondition": "Validate affected product/version and exploit path prerequisites before filing.",
|
|
"reproducibility": "not-reproduced",
|
|
"disposition": "needs-manual-test",
|
|
"disposition_rationale": "Script/banner evidence exists, but no direct proof of exploit impact was captured in scan output.",
|
|
"required_reproduction_step_before_ticket": "Before creating a ticket, reproduce vulnerable behavior directly (e.g., crafted request causing data exposure, traversal read, or exploitable crash) and attach request/response proof. Banner or script signature matches alone are insufficient.",
|
|
"evidence_sources": [
|
|
{
|
|
"file": "results/auth.lan.ddnsgeek.com/scans/_patterns.log",
|
|
"match_count": 4
|
|
}
|
|
]
|
|
},
|
|
{
|
|
"host": "auth.lan.ddnsgeek.com",
|
|
"cve": "CVE-2002-1264",
|
|
"affected_host": "auth.lan.ddnsgeek.com",
|
|
"endpoint": "unknown",
|
|
"product_version_evidence": [
|
|
"http syn-ack ttl 55 Golang net/http server (Go-IPFS json-rpc or InfluxDB API)",
|
|
"http syn-ack ttl 55 Golang net/http server (Go-IPFS json-rpc or InfluxDB API)",
|
|
"http syn-ack ttl 55 Golang net/http server (Go-IPFS json-rpc or InfluxDB API)",
|
|
"ssl/http syn-ack ttl 55 Golang net/http server (Go-IPFS json-rpc or InfluxDB API)",
|
|
"ssl/http syn-ack ttl 55 Golang net/http server (Go-IPFS json-rpc or InfluxDB API)",
|
|
"tcpwrapped syn-ack ttl 56"
|
|
],
|
|
"exploit_precondition": "Validate affected product/version and exploit path prerequisites before filing.",
|
|
"reproducibility": "not-reproduced",
|
|
"disposition": "needs-manual-test",
|
|
"disposition_rationale": "Script/banner evidence exists, but no direct proof of exploit impact was captured in scan output.",
|
|
"required_reproduction_step_before_ticket": "Before creating a ticket, reproduce vulnerable behavior directly (e.g., crafted request causing data exposure, traversal read, or exploitable crash) and attach request/response proof. Banner or script signature matches alone are insufficient.",
|
|
"evidence_sources": [
|
|
{
|
|
"file": "results/auth.lan.ddnsgeek.com/scans/_patterns.log",
|
|
"match_count": 1
|
|
}
|
|
]
|
|
},
|
|
{
|
|
"host": "auth.lan.ddnsgeek.com",
|
|
"cve": "CVE-2002-1353",
|
|
"affected_host": "auth.lan.ddnsgeek.com",
|
|
"endpoint": "unknown",
|
|
"product_version_evidence": [
|
|
"http syn-ack ttl 55 Golang net/http server (Go-IPFS json-rpc or InfluxDB API)",
|
|
"http syn-ack ttl 55 Golang net/http server (Go-IPFS json-rpc or InfluxDB API)",
|
|
"http syn-ack ttl 55 Golang net/http server (Go-IPFS json-rpc or InfluxDB API)",
|
|
"ssl/http syn-ack ttl 55 Golang net/http server (Go-IPFS json-rpc or InfluxDB API)",
|
|
"ssl/http syn-ack ttl 55 Golang net/http server (Go-IPFS json-rpc or InfluxDB API)",
|
|
"tcpwrapped syn-ack ttl 56"
|
|
],
|
|
"exploit_precondition": "Validate affected product/version and exploit path prerequisites before filing.",
|
|
"reproducibility": "not-reproduced",
|
|
"disposition": "needs-manual-test",
|
|
"disposition_rationale": "Script/banner evidence exists, but no direct proof of exploit impact was captured in scan output.",
|
|
"required_reproduction_step_before_ticket": "Before creating a ticket, reproduce vulnerable behavior directly (e.g., crafted request causing data exposure, traversal read, or exploitable crash) and attach request/response proof. Banner or script signature matches alone are insufficient.",
|
|
"evidence_sources": [
|
|
{
|
|
"file": "results/auth.lan.ddnsgeek.com/scans/_patterns.log",
|
|
"match_count": 1
|
|
}
|
|
]
|
|
},
|
|
{
|
|
"host": "auth.lan.ddnsgeek.com",
|
|
"cve": "CVE-2002-1428",
|
|
"affected_host": "auth.lan.ddnsgeek.com",
|
|
"endpoint": "unknown",
|
|
"product_version_evidence": [
|
|
"http syn-ack ttl 55 Golang net/http server (Go-IPFS json-rpc or InfluxDB API)",
|
|
"http syn-ack ttl 55 Golang net/http server (Go-IPFS json-rpc or InfluxDB API)",
|
|
"http syn-ack ttl 55 Golang net/http server (Go-IPFS json-rpc or InfluxDB API)",
|
|
"ssl/http syn-ack ttl 55 Golang net/http server (Go-IPFS json-rpc or InfluxDB API)",
|
|
"ssl/http syn-ack ttl 55 Golang net/http server (Go-IPFS json-rpc or InfluxDB API)",
|
|
"tcpwrapped syn-ack ttl 56"
|
|
],
|
|
"exploit_precondition": "Validate affected product/version and exploit path prerequisites before filing.",
|
|
"reproducibility": "not-reproduced",
|
|
"disposition": "needs-manual-test",
|
|
"disposition_rationale": "Script/banner evidence exists, but no direct proof of exploit impact was captured in scan output.",
|
|
"required_reproduction_step_before_ticket": "Before creating a ticket, reproduce vulnerable behavior directly (e.g., crafted request causing data exposure, traversal read, or exploitable crash) and attach request/response proof. Banner or script signature matches alone are insufficient.",
|
|
"evidence_sources": [
|
|
{
|
|
"file": "results/auth.lan.ddnsgeek.com/scans/_patterns.log",
|
|
"match_count": 1
|
|
}
|
|
]
|
|
},
|
|
{
|
|
"host": "auth.lan.ddnsgeek.com",
|
|
"cve": "CVE-2002-1432",
|
|
"affected_host": "auth.lan.ddnsgeek.com",
|
|
"endpoint": "unknown",
|
|
"product_version_evidence": [
|
|
"http syn-ack ttl 55 Golang net/http server (Go-IPFS json-rpc or InfluxDB API)",
|
|
"http syn-ack ttl 55 Golang net/http server (Go-IPFS json-rpc or InfluxDB API)",
|
|
"http syn-ack ttl 55 Golang net/http server (Go-IPFS json-rpc or InfluxDB API)",
|
|
"ssl/http syn-ack ttl 55 Golang net/http server (Go-IPFS json-rpc or InfluxDB API)",
|
|
"ssl/http syn-ack ttl 55 Golang net/http server (Go-IPFS json-rpc or InfluxDB API)",
|
|
"tcpwrapped syn-ack ttl 56"
|
|
],
|
|
"exploit_precondition": "Validate affected product/version and exploit path prerequisites before filing.",
|
|
"reproducibility": "not-reproduced",
|
|
"disposition": "needs-manual-test",
|
|
"disposition_rationale": "Script/banner evidence exists, but no direct proof of exploit impact was captured in scan output.",
|
|
"required_reproduction_step_before_ticket": "Before creating a ticket, reproduce vulnerable behavior directly (e.g., crafted request causing data exposure, traversal read, or exploitable crash) and attach request/response proof. Banner or script signature matches alone are insufficient.",
|
|
"evidence_sources": [
|
|
{
|
|
"file": "results/auth.lan.ddnsgeek.com/scans/_patterns.log",
|
|
"match_count": 3
|
|
}
|
|
]
|
|
},
|
|
{
|
|
"host": "auth.lan.ddnsgeek.com",
|
|
"cve": "CVE-2002-1436",
|
|
"affected_host": "auth.lan.ddnsgeek.com",
|
|
"endpoint": "unknown",
|
|
"product_version_evidence": [
|
|
"http syn-ack ttl 55 Golang net/http server (Go-IPFS json-rpc or InfluxDB API)",
|
|
"http syn-ack ttl 55 Golang net/http server (Go-IPFS json-rpc or InfluxDB API)",
|
|
"http syn-ack ttl 55 Golang net/http server (Go-IPFS json-rpc or InfluxDB API)",
|
|
"ssl/http syn-ack ttl 55 Golang net/http server (Go-IPFS json-rpc or InfluxDB API)",
|
|
"ssl/http syn-ack ttl 55 Golang net/http server (Go-IPFS json-rpc or InfluxDB API)",
|
|
"tcpwrapped syn-ack ttl 56"
|
|
],
|
|
"exploit_precondition": "Validate affected product/version and exploit path prerequisites before filing.",
|
|
"reproducibility": "not-reproduced",
|
|
"disposition": "needs-manual-test",
|
|
"disposition_rationale": "Script/banner evidence exists, but no direct proof of exploit impact was captured in scan output.",
|
|
"required_reproduction_step_before_ticket": "Before creating a ticket, reproduce vulnerable behavior directly (e.g., crafted request causing data exposure, traversal read, or exploitable crash) and attach request/response proof. Banner or script signature matches alone are insufficient.",
|
|
"evidence_sources": [
|
|
{
|
|
"file": "results/auth.lan.ddnsgeek.com/scans/_patterns.log",
|
|
"match_count": 1
|
|
}
|
|
]
|
|
},
|
|
{
|
|
"host": "auth.lan.ddnsgeek.com",
|
|
"cve": "CVE-2002-1452",
|
|
"affected_host": "auth.lan.ddnsgeek.com",
|
|
"endpoint": "unknown",
|
|
"product_version_evidence": [
|
|
"http syn-ack ttl 55 Golang net/http server (Go-IPFS json-rpc or InfluxDB API)",
|
|
"http syn-ack ttl 55 Golang net/http server (Go-IPFS json-rpc or InfluxDB API)",
|
|
"http syn-ack ttl 55 Golang net/http server (Go-IPFS json-rpc or InfluxDB API)",
|
|
"ssl/http syn-ack ttl 55 Golang net/http server (Go-IPFS json-rpc or InfluxDB API)",
|
|
"ssl/http syn-ack ttl 55 Golang net/http server (Go-IPFS json-rpc or InfluxDB API)",
|
|
"tcpwrapped syn-ack ttl 56"
|
|
],
|
|
"exploit_precondition": "Validate affected product/version and exploit path prerequisites before filing.",
|
|
"reproducibility": "not-reproduced",
|
|
"disposition": "needs-manual-test",
|
|
"disposition_rationale": "Script/banner evidence exists, but no direct proof of exploit impact was captured in scan output.",
|
|
"required_reproduction_step_before_ticket": "Before creating a ticket, reproduce vulnerable behavior directly (e.g., crafted request causing data exposure, traversal read, or exploitable crash) and attach request/response proof. Banner or script signature matches alone are insufficient.",
|
|
"evidence_sources": [
|
|
{
|
|
"file": "results/auth.lan.ddnsgeek.com/scans/_patterns.log",
|
|
"match_count": 1
|
|
}
|
|
]
|
|
},
|
|
{
|
|
"host": "auth.lan.ddnsgeek.com",
|
|
"cve": "CVE-2002-1499",
|
|
"affected_host": "auth.lan.ddnsgeek.com",
|
|
"endpoint": "unknown",
|
|
"product_version_evidence": [
|
|
"http syn-ack ttl 55 Golang net/http server (Go-IPFS json-rpc or InfluxDB API)",
|
|
"http syn-ack ttl 55 Golang net/http server (Go-IPFS json-rpc or InfluxDB API)",
|
|
"http syn-ack ttl 55 Golang net/http server (Go-IPFS json-rpc or InfluxDB API)",
|
|
"ssl/http syn-ack ttl 55 Golang net/http server (Go-IPFS json-rpc or InfluxDB API)",
|
|
"ssl/http syn-ack ttl 55 Golang net/http server (Go-IPFS json-rpc or InfluxDB API)",
|
|
"tcpwrapped syn-ack ttl 56"
|
|
],
|
|
"exploit_precondition": "Validate affected product/version and exploit path prerequisites before filing.",
|
|
"reproducibility": "not-reproduced",
|
|
"disposition": "needs-manual-test",
|
|
"disposition_rationale": "Script/banner evidence exists, but no direct proof of exploit impact was captured in scan output.",
|
|
"required_reproduction_step_before_ticket": "Before creating a ticket, reproduce vulnerable behavior directly (e.g., crafted request causing data exposure, traversal read, or exploitable crash) and attach request/response proof. Banner or script signature matches alone are insufficient.",
|
|
"evidence_sources": [
|
|
{
|
|
"file": "results/auth.lan.ddnsgeek.com/scans/_patterns.log",
|
|
"match_count": 1
|
|
}
|
|
]
|
|
},
|
|
{
|
|
"host": "auth.lan.ddnsgeek.com",
|
|
"cve": "CVE-2002-1560",
|
|
"affected_host": "auth.lan.ddnsgeek.com",
|
|
"endpoint": "unknown",
|
|
"product_version_evidence": [
|
|
"http syn-ack ttl 55 Golang net/http server (Go-IPFS json-rpc or InfluxDB API)",
|
|
"http syn-ack ttl 55 Golang net/http server (Go-IPFS json-rpc or InfluxDB API)",
|
|
"http syn-ack ttl 55 Golang net/http server (Go-IPFS json-rpc or InfluxDB API)",
|
|
"ssl/http syn-ack ttl 55 Golang net/http server (Go-IPFS json-rpc or InfluxDB API)",
|
|
"ssl/http syn-ack ttl 55 Golang net/http server (Go-IPFS json-rpc or InfluxDB API)",
|
|
"tcpwrapped syn-ack ttl 56"
|
|
],
|
|
"exploit_precondition": "Validate affected product/version and exploit path prerequisites before filing.",
|
|
"reproducibility": "not-reproduced",
|
|
"disposition": "needs-manual-test",
|
|
"disposition_rationale": "Script/banner evidence exists, but no direct proof of exploit impact was captured in scan output.",
|
|
"required_reproduction_step_before_ticket": "Before creating a ticket, reproduce vulnerable behavior directly (e.g., crafted request causing data exposure, traversal read, or exploitable crash) and attach request/response proof. Banner or script signature matches alone are insufficient.",
|
|
"evidence_sources": [
|
|
{
|
|
"file": "results/auth.lan.ddnsgeek.com/scans/_patterns.log",
|
|
"match_count": 1
|
|
}
|
|
]
|
|
},
|
|
{
|
|
"host": "auth.lan.ddnsgeek.com",
|
|
"cve": "CVE-2002-1717",
|
|
"affected_host": "auth.lan.ddnsgeek.com",
|
|
"endpoint": "unknown",
|
|
"product_version_evidence": [
|
|
"http syn-ack ttl 55 Golang net/http server (Go-IPFS json-rpc or InfluxDB API)",
|
|
"http syn-ack ttl 55 Golang net/http server (Go-IPFS json-rpc or InfluxDB API)",
|
|
"http syn-ack ttl 55 Golang net/http server (Go-IPFS json-rpc or InfluxDB API)",
|
|
"ssl/http syn-ack ttl 55 Golang net/http server (Go-IPFS json-rpc or InfluxDB API)",
|
|
"ssl/http syn-ack ttl 55 Golang net/http server (Go-IPFS json-rpc or InfluxDB API)",
|
|
"tcpwrapped syn-ack ttl 56"
|
|
],
|
|
"exploit_precondition": "Validate affected product/version and exploit path prerequisites before filing.",
|
|
"reproducibility": "not-reproduced",
|
|
"disposition": "needs-manual-test",
|
|
"disposition_rationale": "Script/banner evidence exists, but no direct proof of exploit impact was captured in scan output.",
|
|
"required_reproduction_step_before_ticket": "Before creating a ticket, reproduce vulnerable behavior directly (e.g., crafted request causing data exposure, traversal read, or exploitable crash) and attach request/response proof. Banner or script signature matches alone are insufficient.",
|
|
"evidence_sources": [
|
|
{
|
|
"file": "results/auth.lan.ddnsgeek.com/scans/_patterns.log",
|
|
"match_count": 6
|
|
}
|
|
]
|
|
},
|
|
{
|
|
"host": "auth.lan.ddnsgeek.com",
|
|
"cve": "CVE-2002-1769",
|
|
"affected_host": "auth.lan.ddnsgeek.com",
|
|
"endpoint": "unknown",
|
|
"product_version_evidence": [
|
|
"http syn-ack ttl 55 Golang net/http server (Go-IPFS json-rpc or InfluxDB API)",
|
|
"http syn-ack ttl 55 Golang net/http server (Go-IPFS json-rpc or InfluxDB API)",
|
|
"http syn-ack ttl 55 Golang net/http server (Go-IPFS json-rpc or InfluxDB API)",
|
|
"ssl/http syn-ack ttl 55 Golang net/http server (Go-IPFS json-rpc or InfluxDB API)",
|
|
"ssl/http syn-ack ttl 55 Golang net/http server (Go-IPFS json-rpc or InfluxDB API)",
|
|
"tcpwrapped syn-ack ttl 56"
|
|
],
|
|
"exploit_precondition": "Validate affected product/version and exploit path prerequisites before filing.",
|
|
"reproducibility": "not-reproduced",
|
|
"disposition": "needs-manual-test",
|
|
"disposition_rationale": "Script/banner evidence exists, but no direct proof of exploit impact was captured in scan output.",
|
|
"required_reproduction_step_before_ticket": "Before creating a ticket, reproduce vulnerable behavior directly (e.g., crafted request causing data exposure, traversal read, or exploitable crash) and attach request/response proof. Banner or script signature matches alone are insufficient.",
|
|
"evidence_sources": [
|
|
{
|
|
"file": "results/auth.lan.ddnsgeek.com/scans/_patterns.log",
|
|
"match_count": 5
|
|
}
|
|
]
|
|
},
|
|
{
|
|
"host": "auth.lan.ddnsgeek.com",
|
|
"cve": "CVE-2002-2057",
|
|
"affected_host": "auth.lan.ddnsgeek.com",
|
|
"endpoint": "unknown",
|
|
"product_version_evidence": [
|
|
"http syn-ack ttl 55 Golang net/http server (Go-IPFS json-rpc or InfluxDB API)",
|
|
"http syn-ack ttl 55 Golang net/http server (Go-IPFS json-rpc or InfluxDB API)",
|
|
"http syn-ack ttl 55 Golang net/http server (Go-IPFS json-rpc or InfluxDB API)",
|
|
"ssl/http syn-ack ttl 55 Golang net/http server (Go-IPFS json-rpc or InfluxDB API)",
|
|
"ssl/http syn-ack ttl 55 Golang net/http server (Go-IPFS json-rpc or InfluxDB API)",
|
|
"tcpwrapped syn-ack ttl 56"
|
|
],
|
|
"exploit_precondition": "Validate affected product/version and exploit path prerequisites before filing.",
|
|
"reproducibility": "not-reproduced",
|
|
"disposition": "needs-manual-test",
|
|
"disposition_rationale": "Script/banner evidence exists, but no direct proof of exploit impact was captured in scan output.",
|
|
"required_reproduction_step_before_ticket": "Before creating a ticket, reproduce vulnerable behavior directly (e.g., crafted request causing data exposure, traversal read, or exploitable crash) and attach request/response proof. Banner or script signature matches alone are insufficient.",
|
|
"evidence_sources": [
|
|
{
|
|
"file": "results/auth.lan.ddnsgeek.com/scans/_patterns.log",
|
|
"match_count": 1
|
|
}
|
|
]
|
|
},
|
|
{
|
|
"host": "auth.lan.ddnsgeek.com",
|
|
"cve": "CVE-2002-2058",
|
|
"affected_host": "auth.lan.ddnsgeek.com",
|
|
"endpoint": "unknown",
|
|
"product_version_evidence": [
|
|
"http syn-ack ttl 55 Golang net/http server (Go-IPFS json-rpc or InfluxDB API)",
|
|
"http syn-ack ttl 55 Golang net/http server (Go-IPFS json-rpc or InfluxDB API)",
|
|
"http syn-ack ttl 55 Golang net/http server (Go-IPFS json-rpc or InfluxDB API)",
|
|
"ssl/http syn-ack ttl 55 Golang net/http server (Go-IPFS json-rpc or InfluxDB API)",
|
|
"ssl/http syn-ack ttl 55 Golang net/http server (Go-IPFS json-rpc or InfluxDB API)",
|
|
"tcpwrapped syn-ack ttl 56"
|
|
],
|
|
"exploit_precondition": "Validate affected product/version and exploit path prerequisites before filing.",
|
|
"reproducibility": "not-reproduced",
|
|
"disposition": "needs-manual-test",
|
|
"disposition_rationale": "Script/banner evidence exists, but no direct proof of exploit impact was captured in scan output.",
|
|
"required_reproduction_step_before_ticket": "Before creating a ticket, reproduce vulnerable behavior directly (e.g., crafted request causing data exposure, traversal read, or exploitable crash) and attach request/response proof. Banner or script signature matches alone are insufficient.",
|
|
"evidence_sources": [
|
|
{
|
|
"file": "results/auth.lan.ddnsgeek.com/scans/_patterns.log",
|
|
"match_count": 2
|
|
}
|
|
]
|
|
},
|
|
{
|
|
"host": "auth.lan.ddnsgeek.com",
|
|
"cve": "CVE-2002-2320",
|
|
"affected_host": "auth.lan.ddnsgeek.com",
|
|
"endpoint": "unknown",
|
|
"product_version_evidence": [
|
|
"http syn-ack ttl 55 Golang net/http server (Go-IPFS json-rpc or InfluxDB API)",
|
|
"http syn-ack ttl 55 Golang net/http server (Go-IPFS json-rpc or InfluxDB API)",
|
|
"http syn-ack ttl 55 Golang net/http server (Go-IPFS json-rpc or InfluxDB API)",
|
|
"ssl/http syn-ack ttl 55 Golang net/http server (Go-IPFS json-rpc or InfluxDB API)",
|
|
"ssl/http syn-ack ttl 55 Golang net/http server (Go-IPFS json-rpc or InfluxDB API)",
|
|
"tcpwrapped syn-ack ttl 56"
|
|
],
|
|
"exploit_precondition": "Validate affected product/version and exploit path prerequisites before filing.",
|
|
"reproducibility": "not-reproduced",
|
|
"disposition": "needs-manual-test",
|
|
"disposition_rationale": "Script/banner evidence exists, but no direct proof of exploit impact was captured in scan output.",
|
|
"required_reproduction_step_before_ticket": "Before creating a ticket, reproduce vulnerable behavior directly (e.g., crafted request causing data exposure, traversal read, or exploitable crash) and attach request/response proof. Banner or script signature matches alone are insufficient.",
|
|
"evidence_sources": [
|
|
{
|
|
"file": "results/auth.lan.ddnsgeek.com/scans/_patterns.log",
|
|
"match_count": 1
|
|
}
|
|
]
|
|
},
|
|
{
|
|
"host": "auth.lan.ddnsgeek.com",
|
|
"cve": "CVE-2002-2342",
|
|
"affected_host": "auth.lan.ddnsgeek.com",
|
|
"endpoint": "unknown",
|
|
"product_version_evidence": [
|
|
"http syn-ack ttl 55 Golang net/http server (Go-IPFS json-rpc or InfluxDB API)",
|
|
"http syn-ack ttl 55 Golang net/http server (Go-IPFS json-rpc or InfluxDB API)",
|
|
"http syn-ack ttl 55 Golang net/http server (Go-IPFS json-rpc or InfluxDB API)",
|
|
"ssl/http syn-ack ttl 55 Golang net/http server (Go-IPFS json-rpc or InfluxDB API)",
|
|
"ssl/http syn-ack ttl 55 Golang net/http server (Go-IPFS json-rpc or InfluxDB API)",
|
|
"tcpwrapped syn-ack ttl 56"
|
|
],
|
|
"exploit_precondition": "Validate affected product/version and exploit path prerequisites before filing.",
|
|
"reproducibility": "not-reproduced",
|
|
"disposition": "needs-manual-test",
|
|
"disposition_rationale": "Script/banner evidence exists, but no direct proof of exploit impact was captured in scan output.",
|
|
"required_reproduction_step_before_ticket": "Before creating a ticket, reproduce vulnerable behavior directly (e.g., crafted request causing data exposure, traversal read, or exploitable crash) and attach request/response proof. Banner or script signature matches alone are insufficient.",
|
|
"evidence_sources": [
|
|
{
|
|
"file": "results/auth.lan.ddnsgeek.com/scans/_patterns.log",
|
|
"match_count": 4
|
|
}
|
|
]
|
|
},
|
|
{
|
|
"host": "auth.lan.ddnsgeek.com",
|
|
"cve": "CVE-2003-0169",
|
|
"affected_host": "auth.lan.ddnsgeek.com",
|
|
"endpoint": "unknown",
|
|
"product_version_evidence": [
|
|
"http syn-ack ttl 55 Golang net/http server (Go-IPFS json-rpc or InfluxDB API)",
|
|
"http syn-ack ttl 55 Golang net/http server (Go-IPFS json-rpc or InfluxDB API)",
|
|
"http syn-ack ttl 55 Golang net/http server (Go-IPFS json-rpc or InfluxDB API)",
|
|
"ssl/http syn-ack ttl 55 Golang net/http server (Go-IPFS json-rpc or InfluxDB API)",
|
|
"ssl/http syn-ack ttl 55 Golang net/http server (Go-IPFS json-rpc or InfluxDB API)",
|
|
"tcpwrapped syn-ack ttl 56"
|
|
],
|
|
"exploit_precondition": "Validate affected product/version and exploit path prerequisites before filing.",
|
|
"reproducibility": "not-reproduced",
|
|
"disposition": "needs-manual-test",
|
|
"disposition_rationale": "Script/banner evidence exists, but no direct proof of exploit impact was captured in scan output.",
|
|
"required_reproduction_step_before_ticket": "Before creating a ticket, reproduce vulnerable behavior directly (e.g., crafted request causing data exposure, traversal read, or exploitable crash) and attach request/response proof. Banner or script signature matches alone are insufficient.",
|
|
"evidence_sources": [
|
|
{
|
|
"file": "results/auth.lan.ddnsgeek.com/scans/_patterns.log",
|
|
"match_count": 1
|
|
}
|
|
]
|
|
},
|
|
{
|
|
"host": "auth.lan.ddnsgeek.com",
|
|
"cve": "CVE-2003-0240",
|
|
"affected_host": "auth.lan.ddnsgeek.com",
|
|
"endpoint": "unknown",
|
|
"product_version_evidence": [
|
|
"http syn-ack ttl 55 Golang net/http server (Go-IPFS json-rpc or InfluxDB API)",
|
|
"http syn-ack ttl 55 Golang net/http server (Go-IPFS json-rpc or InfluxDB API)",
|
|
"http syn-ack ttl 55 Golang net/http server (Go-IPFS json-rpc or InfluxDB API)",
|
|
"ssl/http syn-ack ttl 55 Golang net/http server (Go-IPFS json-rpc or InfluxDB API)",
|
|
"ssl/http syn-ack ttl 55 Golang net/http server (Go-IPFS json-rpc or InfluxDB API)",
|
|
"tcpwrapped syn-ack ttl 56"
|
|
],
|
|
"exploit_precondition": "Validate affected product/version and exploit path prerequisites before filing.",
|
|
"reproducibility": "not-reproduced",
|
|
"disposition": "needs-manual-test",
|
|
"disposition_rationale": "Script/banner evidence exists, but no direct proof of exploit impact was captured in scan output.",
|
|
"required_reproduction_step_before_ticket": "Before creating a ticket, reproduce vulnerable behavior directly (e.g., crafted request causing data exposure, traversal read, or exploitable crash) and attach request/response proof. Banner or script signature matches alone are insufficient.",
|
|
"evidence_sources": [
|
|
{
|
|
"file": "results/auth.lan.ddnsgeek.com/scans/_patterns.log",
|
|
"match_count": 1
|
|
}
|
|
]
|
|
},
|
|
{
|
|
"host": "auth.lan.ddnsgeek.com",
|
|
"cve": "CVE-2003-0401",
|
|
"affected_host": "auth.lan.ddnsgeek.com",
|
|
"endpoint": "unknown",
|
|
"product_version_evidence": [
|
|
"http syn-ack ttl 55 Golang net/http server (Go-IPFS json-rpc or InfluxDB API)",
|
|
"http syn-ack ttl 55 Golang net/http server (Go-IPFS json-rpc or InfluxDB API)",
|
|
"http syn-ack ttl 55 Golang net/http server (Go-IPFS json-rpc or InfluxDB API)",
|
|
"ssl/http syn-ack ttl 55 Golang net/http server (Go-IPFS json-rpc or InfluxDB API)",
|
|
"ssl/http syn-ack ttl 55 Golang net/http server (Go-IPFS json-rpc or InfluxDB API)",
|
|
"tcpwrapped syn-ack ttl 56"
|
|
],
|
|
"exploit_precondition": "Validate affected product/version and exploit path prerequisites before filing.",
|
|
"reproducibility": "not-reproduced",
|
|
"disposition": "needs-manual-test",
|
|
"disposition_rationale": "Script/banner evidence exists, but no direct proof of exploit impact was captured in scan output.",
|
|
"required_reproduction_step_before_ticket": "Before creating a ticket, reproduce vulnerable behavior directly (e.g., crafted request causing data exposure, traversal read, or exploitable crash) and attach request/response proof. Banner or script signature matches alone are insufficient.",
|
|
"evidence_sources": [
|
|
{
|
|
"file": "results/auth.lan.ddnsgeek.com/scans/_patterns.log",
|
|
"match_count": 1
|
|
}
|
|
]
|
|
},
|
|
{
|
|
"host": "auth.lan.ddnsgeek.com",
|
|
"cve": "CVE-2003-0403",
|
|
"affected_host": "auth.lan.ddnsgeek.com",
|
|
"endpoint": "unknown",
|
|
"product_version_evidence": [
|
|
"http syn-ack ttl 55 Golang net/http server (Go-IPFS json-rpc or InfluxDB API)",
|
|
"http syn-ack ttl 55 Golang net/http server (Go-IPFS json-rpc or InfluxDB API)",
|
|
"http syn-ack ttl 55 Golang net/http server (Go-IPFS json-rpc or InfluxDB API)",
|
|
"ssl/http syn-ack ttl 55 Golang net/http server (Go-IPFS json-rpc or InfluxDB API)",
|
|
"ssl/http syn-ack ttl 55 Golang net/http server (Go-IPFS json-rpc or InfluxDB API)",
|
|
"tcpwrapped syn-ack ttl 56"
|
|
],
|
|
"exploit_precondition": "Validate affected product/version and exploit path prerequisites before filing.",
|
|
"reproducibility": "not-reproduced",
|
|
"disposition": "needs-manual-test",
|
|
"disposition_rationale": "Script/banner evidence exists, but no direct proof of exploit impact was captured in scan output.",
|
|
"required_reproduction_step_before_ticket": "Before creating a ticket, reproduce vulnerable behavior directly (e.g., crafted request causing data exposure, traversal read, or exploitable crash) and attach request/response proof. Banner or script signature matches alone are insufficient.",
|
|
"evidence_sources": [
|
|
{
|
|
"file": "results/auth.lan.ddnsgeek.com/scans/_patterns.log",
|
|
"match_count": 1
|
|
}
|
|
]
|
|
},
|
|
{
|
|
"host": "auth.lan.ddnsgeek.com",
|
|
"cve": "CVE-2003-0560",
|
|
"affected_host": "auth.lan.ddnsgeek.com",
|
|
"endpoint": "unknown",
|
|
"product_version_evidence": [
|
|
"http syn-ack ttl 55 Golang net/http server (Go-IPFS json-rpc or InfluxDB API)",
|
|
"http syn-ack ttl 55 Golang net/http server (Go-IPFS json-rpc or InfluxDB API)",
|
|
"http syn-ack ttl 55 Golang net/http server (Go-IPFS json-rpc or InfluxDB API)",
|
|
"ssl/http syn-ack ttl 55 Golang net/http server (Go-IPFS json-rpc or InfluxDB API)",
|
|
"ssl/http syn-ack ttl 55 Golang net/http server (Go-IPFS json-rpc or InfluxDB API)",
|
|
"tcpwrapped syn-ack ttl 56"
|
|
],
|
|
"exploit_precondition": "Validate affected product/version and exploit path prerequisites before filing.",
|
|
"reproducibility": "not-reproduced",
|
|
"disposition": "needs-manual-test",
|
|
"disposition_rationale": "Script/banner evidence exists, but no direct proof of exploit impact was captured in scan output.",
|
|
"required_reproduction_step_before_ticket": "Before creating a ticket, reproduce vulnerable behavior directly (e.g., crafted request causing data exposure, traversal read, or exploitable crash) and attach request/response proof. Banner or script signature matches alone are insufficient.",
|
|
"evidence_sources": [
|
|
{
|
|
"file": "results/auth.lan.ddnsgeek.com/scans/_patterns.log",
|
|
"match_count": 1
|
|
}
|
|
]
|
|
},
|
|
{
|
|
"host": "auth.lan.ddnsgeek.com",
|
|
"cve": "CVE-2003-1140",
|
|
"affected_host": "auth.lan.ddnsgeek.com",
|
|
"endpoint": "unknown",
|
|
"product_version_evidence": [
|
|
"http syn-ack ttl 55 Golang net/http server (Go-IPFS json-rpc or InfluxDB API)",
|
|
"http syn-ack ttl 55 Golang net/http server (Go-IPFS json-rpc or InfluxDB API)",
|
|
"http syn-ack ttl 55 Golang net/http server (Go-IPFS json-rpc or InfluxDB API)",
|
|
"ssl/http syn-ack ttl 55 Golang net/http server (Go-IPFS json-rpc or InfluxDB API)",
|
|
"ssl/http syn-ack ttl 55 Golang net/http server (Go-IPFS json-rpc or InfluxDB API)",
|
|
"tcpwrapped syn-ack ttl 56"
|
|
],
|
|
"exploit_precondition": "Validate affected product/version and exploit path prerequisites before filing.",
|
|
"reproducibility": "not-reproduced",
|
|
"disposition": "needs-manual-test",
|
|
"disposition_rationale": "Script/banner evidence exists, but no direct proof of exploit impact was captured in scan output.",
|
|
"required_reproduction_step_before_ticket": "Before creating a ticket, reproduce vulnerable behavior directly (e.g., crafted request causing data exposure, traversal read, or exploitable crash) and attach request/response proof. Banner or script signature matches alone are insufficient.",
|
|
"evidence_sources": [
|
|
{
|
|
"file": "results/auth.lan.ddnsgeek.com/scans/_patterns.log",
|
|
"match_count": 1
|
|
}
|
|
]
|
|
},
|
|
{
|
|
"host": "auth.lan.ddnsgeek.com",
|
|
"cve": "CVE-2003-1383",
|
|
"affected_host": "auth.lan.ddnsgeek.com",
|
|
"endpoint": "unknown",
|
|
"product_version_evidence": [
|
|
"http syn-ack ttl 55 Golang net/http server (Go-IPFS json-rpc or InfluxDB API)",
|
|
"http syn-ack ttl 55 Golang net/http server (Go-IPFS json-rpc or InfluxDB API)",
|
|
"http syn-ack ttl 55 Golang net/http server (Go-IPFS json-rpc or InfluxDB API)",
|
|
"ssl/http syn-ack ttl 55 Golang net/http server (Go-IPFS json-rpc or InfluxDB API)",
|
|
"ssl/http syn-ack ttl 55 Golang net/http server (Go-IPFS json-rpc or InfluxDB API)",
|
|
"tcpwrapped syn-ack ttl 56"
|
|
],
|
|
"exploit_precondition": "Validate affected product/version and exploit path prerequisites before filing.",
|
|
"reproducibility": "not-reproduced",
|
|
"disposition": "needs-manual-test",
|
|
"disposition_rationale": "Script/banner evidence exists, but no direct proof of exploit impact was captured in scan output.",
|
|
"required_reproduction_step_before_ticket": "Before creating a ticket, reproduce vulnerable behavior directly (e.g., crafted request causing data exposure, traversal read, or exploitable crash) and attach request/response proof. Banner or script signature matches alone are insufficient.",
|
|
"evidence_sources": [
|
|
{
|
|
"file": "results/auth.lan.ddnsgeek.com/scans/_patterns.log",
|
|
"match_count": 1
|
|
}
|
|
]
|
|
},
|
|
{
|
|
"host": "auth.lan.ddnsgeek.com",
|
|
"cve": "CVE-2004-1873",
|
|
"affected_host": "auth.lan.ddnsgeek.com",
|
|
"endpoint": "unknown",
|
|
"product_version_evidence": [
|
|
"http syn-ack ttl 55 Golang net/http server (Go-IPFS json-rpc or InfluxDB API)",
|
|
"http syn-ack ttl 55 Golang net/http server (Go-IPFS json-rpc or InfluxDB API)",
|
|
"http syn-ack ttl 55 Golang net/http server (Go-IPFS json-rpc or InfluxDB API)",
|
|
"ssl/http syn-ack ttl 55 Golang net/http server (Go-IPFS json-rpc or InfluxDB API)",
|
|
"ssl/http syn-ack ttl 55 Golang net/http server (Go-IPFS json-rpc or InfluxDB API)",
|
|
"tcpwrapped syn-ack ttl 56"
|
|
],
|
|
"exploit_precondition": "Validate affected product/version and exploit path prerequisites before filing.",
|
|
"reproducibility": "not-reproduced",
|
|
"disposition": "needs-manual-test",
|
|
"disposition_rationale": "Script/banner evidence exists, but no direct proof of exploit impact was captured in scan output.",
|
|
"required_reproduction_step_before_ticket": "Before creating a ticket, reproduce vulnerable behavior directly (e.g., crafted request causing data exposure, traversal read, or exploitable crash) and attach request/response proof. Banner or script signature matches alone are insufficient.",
|
|
"evidence_sources": [
|
|
{
|
|
"file": "results/auth.lan.ddnsgeek.com/scans/_patterns.log",
|
|
"match_count": 1
|
|
}
|
|
]
|
|
},
|
|
{
|
|
"host": "auth.lan.ddnsgeek.com",
|
|
"cve": "CVE-2004-2104",
|
|
"affected_host": "auth.lan.ddnsgeek.com",
|
|
"endpoint": "unknown",
|
|
"product_version_evidence": [
|
|
"http syn-ack ttl 55 Golang net/http server (Go-IPFS json-rpc or InfluxDB API)",
|
|
"http syn-ack ttl 55 Golang net/http server (Go-IPFS json-rpc or InfluxDB API)",
|
|
"http syn-ack ttl 55 Golang net/http server (Go-IPFS json-rpc or InfluxDB API)",
|
|
"ssl/http syn-ack ttl 55 Golang net/http server (Go-IPFS json-rpc or InfluxDB API)",
|
|
"ssl/http syn-ack ttl 55 Golang net/http server (Go-IPFS json-rpc or InfluxDB API)",
|
|
"tcpwrapped syn-ack ttl 56"
|
|
],
|
|
"exploit_precondition": "Validate affected product/version and exploit path prerequisites before filing.",
|
|
"reproducibility": "not-reproduced",
|
|
"disposition": "needs-manual-test",
|
|
"disposition_rationale": "Script/banner evidence exists, but no direct proof of exploit impact was captured in scan output.",
|
|
"required_reproduction_step_before_ticket": "Before creating a ticket, reproduce vulnerable behavior directly (e.g., crafted request causing data exposure, traversal read, or exploitable crash) and attach request/response proof. Banner or script signature matches alone are insufficient.",
|
|
"evidence_sources": [
|
|
{
|
|
"file": "results/auth.lan.ddnsgeek.com/scans/_patterns.log",
|
|
"match_count": 2
|
|
}
|
|
]
|
|
},
|
|
{
|
|
"host": "auth.lan.ddnsgeek.com",
|
|
"cve": "CVE-2004-2106",
|
|
"affected_host": "auth.lan.ddnsgeek.com",
|
|
"endpoint": "unknown",
|
|
"product_version_evidence": [
|
|
"http syn-ack ttl 55 Golang net/http server (Go-IPFS json-rpc or InfluxDB API)",
|
|
"http syn-ack ttl 55 Golang net/http server (Go-IPFS json-rpc or InfluxDB API)",
|
|
"http syn-ack ttl 55 Golang net/http server (Go-IPFS json-rpc or InfluxDB API)",
|
|
"ssl/http syn-ack ttl 55 Golang net/http server (Go-IPFS json-rpc or InfluxDB API)",
|
|
"ssl/http syn-ack ttl 55 Golang net/http server (Go-IPFS json-rpc or InfluxDB API)",
|
|
"tcpwrapped syn-ack ttl 56"
|
|
],
|
|
"exploit_precondition": "Validate affected product/version and exploit path prerequisites before filing.",
|
|
"reproducibility": "not-reproduced",
|
|
"disposition": "needs-manual-test",
|
|
"disposition_rationale": "Script/banner evidence exists, but no direct proof of exploit impact was captured in scan output.",
|
|
"required_reproduction_step_before_ticket": "Before creating a ticket, reproduce vulnerable behavior directly (e.g., crafted request causing data exposure, traversal read, or exploitable crash) and attach request/response proof. Banner or script signature matches alone are insufficient.",
|
|
"evidence_sources": [
|
|
{
|
|
"file": "results/auth.lan.ddnsgeek.com/scans/_patterns.log",
|
|
"match_count": 3
|
|
}
|
|
]
|
|
},
|
|
{
|
|
"host": "auth.lan.ddnsgeek.com",
|
|
"cve": "CVE-2005-0595",
|
|
"affected_host": "auth.lan.ddnsgeek.com",
|
|
"endpoint": "unknown",
|
|
"product_version_evidence": [
|
|
"http syn-ack ttl 55 Golang net/http server (Go-IPFS json-rpc or InfluxDB API)",
|
|
"http syn-ack ttl 55 Golang net/http server (Go-IPFS json-rpc or InfluxDB API)",
|
|
"http syn-ack ttl 55 Golang net/http server (Go-IPFS json-rpc or InfluxDB API)",
|
|
"ssl/http syn-ack ttl 55 Golang net/http server (Go-IPFS json-rpc or InfluxDB API)",
|
|
"ssl/http syn-ack ttl 55 Golang net/http server (Go-IPFS json-rpc or InfluxDB API)",
|
|
"tcpwrapped syn-ack ttl 56"
|
|
],
|
|
"exploit_precondition": "Validate affected product/version and exploit path prerequisites before filing.",
|
|
"reproducibility": "not-reproduced",
|
|
"disposition": "needs-manual-test",
|
|
"disposition_rationale": "Script/banner evidence exists, but no direct proof of exploit impact was captured in scan output.",
|
|
"required_reproduction_step_before_ticket": "Before creating a ticket, reproduce vulnerable behavior directly (e.g., crafted request causing data exposure, traversal read, or exploitable crash) and attach request/response proof. Banner or script signature matches alone are insufficient.",
|
|
"evidence_sources": [
|
|
{
|
|
"file": "results/auth.lan.ddnsgeek.com/scans/_patterns.log",
|
|
"match_count": 1
|
|
}
|
|
]
|
|
},
|
|
{
|
|
"host": "auth.lan.ddnsgeek.com",
|
|
"cve": "CVE-2005-1247",
|
|
"affected_host": "auth.lan.ddnsgeek.com",
|
|
"endpoint": "unknown",
|
|
"product_version_evidence": [
|
|
"http syn-ack ttl 55 Golang net/http server (Go-IPFS json-rpc or InfluxDB API)",
|
|
"http syn-ack ttl 55 Golang net/http server (Go-IPFS json-rpc or InfluxDB API)",
|
|
"http syn-ack ttl 55 Golang net/http server (Go-IPFS json-rpc or InfluxDB API)",
|
|
"ssl/http syn-ack ttl 55 Golang net/http server (Go-IPFS json-rpc or InfluxDB API)",
|
|
"ssl/http syn-ack ttl 55 Golang net/http server (Go-IPFS json-rpc or InfluxDB API)",
|
|
"tcpwrapped syn-ack ttl 56"
|
|
],
|
|
"exploit_precondition": "Validate affected product/version and exploit path prerequisites before filing.",
|
|
"reproducibility": "not-reproduced",
|
|
"disposition": "needs-manual-test",
|
|
"disposition_rationale": "Script/banner evidence exists, but no direct proof of exploit impact was captured in scan output.",
|
|
"required_reproduction_step_before_ticket": "Before creating a ticket, reproduce vulnerable behavior directly (e.g., crafted request causing data exposure, traversal read, or exploitable crash) and attach request/response proof. Banner or script signature matches alone are insufficient.",
|
|
"evidence_sources": [
|
|
{
|
|
"file": "results/auth.lan.ddnsgeek.com/scans/_patterns.log",
|
|
"match_count": 1
|
|
}
|
|
]
|
|
},
|
|
{
|
|
"host": "auth.lan.ddnsgeek.com",
|
|
"cve": "CVE-2005-3299",
|
|
"affected_host": "auth.lan.ddnsgeek.com",
|
|
"endpoint": "443/tcp",
|
|
"product_version_evidence": [
|
|
"ssl/http syn-ack ttl 55 Golang net/http server (Go-IPFS json-rpc or InfluxDB API)",
|
|
"ssl/http syn-ack ttl 55 Golang net/http server (Go-IPFS json-rpc or InfluxDB API)"
|
|
],
|
|
"exploit_precondition": "Target must run Apache 2.0.x with mod_imap module enabled and vulnerable to cross-site scripting behavior.",
|
|
"reproducibility": "not-reproduced",
|
|
"disposition": "needs-manual-test",
|
|
"disposition_rationale": "Script/banner evidence exists, but no direct proof of exploit impact was captured in scan output.",
|
|
"required_reproduction_step_before_ticket": "Before creating a ticket, reproduce vulnerable behavior directly (e.g., crafted request causing data exposure, traversal read, or exploitable crash) and attach request/response proof. Banner or script signature matches alone are insufficient.",
|
|
"evidence_sources": [
|
|
{
|
|
"file": "results/auth.lan.ddnsgeek.com/scans/_patterns.log",
|
|
"match_count": 2
|
|
},
|
|
{
|
|
"file": "results/auth.lan.ddnsgeek.com/scans/tcp443/tcp_443_https_nmap.txt",
|
|
"endpoint": "443/tcp",
|
|
"evidence": "| IDs: CVE:CVE-2005-3299"
|
|
},
|
|
{
|
|
"file": "results/auth.lan.ddnsgeek.com/scans/tcp443/tcp_443_https_nmap.txt",
|
|
"endpoint": "443/tcp",
|
|
"evidence": "| https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-3299"
|
|
}
|
|
]
|
|
},
|
|
{
|
|
"host": "auth.lan.ddnsgeek.com",
|
|
"cve": "CVE-2006-2948",
|
|
"affected_host": "auth.lan.ddnsgeek.com",
|
|
"endpoint": "unknown",
|
|
"product_version_evidence": [
|
|
"http syn-ack ttl 55 Golang net/http server (Go-IPFS json-rpc or InfluxDB API)",
|
|
"http syn-ack ttl 55 Golang net/http server (Go-IPFS json-rpc or InfluxDB API)",
|
|
"http syn-ack ttl 55 Golang net/http server (Go-IPFS json-rpc or InfluxDB API)",
|
|
"ssl/http syn-ack ttl 55 Golang net/http server (Go-IPFS json-rpc or InfluxDB API)",
|
|
"ssl/http syn-ack ttl 55 Golang net/http server (Go-IPFS json-rpc or InfluxDB API)",
|
|
"tcpwrapped syn-ack ttl 56"
|
|
],
|
|
"exploit_precondition": "Validate affected product/version and exploit path prerequisites before filing.",
|
|
"reproducibility": "not-reproduced",
|
|
"disposition": "needs-manual-test",
|
|
"disposition_rationale": "Script/banner evidence exists, but no direct proof of exploit impact was captured in scan output.",
|
|
"required_reproduction_step_before_ticket": "Before creating a ticket, reproduce vulnerable behavior directly (e.g., crafted request causing data exposure, traversal read, or exploitable crash) and attach request/response proof. Banner or script signature matches alone are insufficient.",
|
|
"evidence_sources": [
|
|
{
|
|
"file": "results/auth.lan.ddnsgeek.com/scans/_patterns.log",
|
|
"match_count": 1
|
|
}
|
|
]
|
|
},
|
|
{
|
|
"host": "auth.lan.ddnsgeek.com",
|
|
"cve": "CVE-2006-3604",
|
|
"affected_host": "auth.lan.ddnsgeek.com",
|
|
"endpoint": "unknown",
|
|
"product_version_evidence": [
|
|
"http syn-ack ttl 55 Golang net/http server (Go-IPFS json-rpc or InfluxDB API)",
|
|
"http syn-ack ttl 55 Golang net/http server (Go-IPFS json-rpc or InfluxDB API)",
|
|
"http syn-ack ttl 55 Golang net/http server (Go-IPFS json-rpc or InfluxDB API)",
|
|
"ssl/http syn-ack ttl 55 Golang net/http server (Go-IPFS json-rpc or InfluxDB API)",
|
|
"ssl/http syn-ack ttl 55 Golang net/http server (Go-IPFS json-rpc or InfluxDB API)",
|
|
"tcpwrapped syn-ack ttl 56"
|
|
],
|
|
"exploit_precondition": "Validate affected product/version and exploit path prerequisites before filing.",
|
|
"reproducibility": "not-reproduced",
|
|
"disposition": "needs-manual-test",
|
|
"disposition_rationale": "Script/banner evidence exists, but no direct proof of exploit impact was captured in scan output.",
|
|
"required_reproduction_step_before_ticket": "Before creating a ticket, reproduce vulnerable behavior directly (e.g., crafted request causing data exposure, traversal read, or exploitable crash) and attach request/response proof. Banner or script signature matches alone are insufficient.",
|
|
"evidence_sources": [
|
|
{
|
|
"file": "results/auth.lan.ddnsgeek.com/scans/_patterns.log",
|
|
"match_count": 1
|
|
}
|
|
]
|
|
},
|
|
{
|
|
"host": "auth.lan.ddnsgeek.com",
|
|
"cve": "CVE-2006-5412",
|
|
"affected_host": "auth.lan.ddnsgeek.com",
|
|
"endpoint": "unknown",
|
|
"product_version_evidence": [
|
|
"http syn-ack ttl 55 Golang net/http server (Go-IPFS json-rpc or InfluxDB API)",
|
|
"http syn-ack ttl 55 Golang net/http server (Go-IPFS json-rpc or InfluxDB API)",
|
|
"http syn-ack ttl 55 Golang net/http server (Go-IPFS json-rpc or InfluxDB API)",
|
|
"ssl/http syn-ack ttl 55 Golang net/http server (Go-IPFS json-rpc or InfluxDB API)",
|
|
"ssl/http syn-ack ttl 55 Golang net/http server (Go-IPFS json-rpc or InfluxDB API)",
|
|
"tcpwrapped syn-ack ttl 56"
|
|
],
|
|
"exploit_precondition": "Validate affected product/version and exploit path prerequisites before filing.",
|
|
"reproducibility": "not-reproduced",
|
|
"disposition": "needs-manual-test",
|
|
"disposition_rationale": "Script/banner evidence exists, but no direct proof of exploit impact was captured in scan output.",
|
|
"required_reproduction_step_before_ticket": "Before creating a ticket, reproduce vulnerable behavior directly (e.g., crafted request causing data exposure, traversal read, or exploitable crash) and attach request/response proof. Banner or script signature matches alone are insufficient.",
|
|
"evidence_sources": [
|
|
{
|
|
"file": "results/auth.lan.ddnsgeek.com/scans/_patterns.log",
|
|
"match_count": 2
|
|
}
|
|
]
|
|
},
|
|
{
|
|
"host": "auth.lan.ddnsgeek.com",
|
|
"cve": "CVE-2006-6795",
|
|
"affected_host": "auth.lan.ddnsgeek.com",
|
|
"endpoint": "unknown",
|
|
"product_version_evidence": [
|
|
"http syn-ack ttl 55 Golang net/http server (Go-IPFS json-rpc or InfluxDB API)",
|
|
"http syn-ack ttl 55 Golang net/http server (Go-IPFS json-rpc or InfluxDB API)",
|
|
"http syn-ack ttl 55 Golang net/http server (Go-IPFS json-rpc or InfluxDB API)",
|
|
"ssl/http syn-ack ttl 55 Golang net/http server (Go-IPFS json-rpc or InfluxDB API)",
|
|
"ssl/http syn-ack ttl 55 Golang net/http server (Go-IPFS json-rpc or InfluxDB API)",
|
|
"tcpwrapped syn-ack ttl 56"
|
|
],
|
|
"exploit_precondition": "Validate affected product/version and exploit path prerequisites before filing.",
|
|
"reproducibility": "not-reproduced",
|
|
"disposition": "needs-manual-test",
|
|
"disposition_rationale": "Script/banner evidence exists, but no direct proof of exploit impact was captured in scan output.",
|
|
"required_reproduction_step_before_ticket": "Before creating a ticket, reproduce vulnerable behavior directly (e.g., crafted request causing data exposure, traversal read, or exploitable crash) and attach request/response proof. Banner or script signature matches alone are insufficient.",
|
|
"evidence_sources": [
|
|
{
|
|
"file": "results/auth.lan.ddnsgeek.com/scans/_patterns.log",
|
|
"match_count": 6
|
|
}
|
|
]
|
|
},
|
|
{
|
|
"host": "auth.lan.ddnsgeek.com",
|
|
"cve": "CVE-2009-3733",
|
|
"affected_host": "auth.lan.ddnsgeek.com",
|
|
"endpoint": "/sdk/%2E%2E/%2E%2E/%2E%2E/%2E%2E/%2E%2E/%2E%2E/%2E%2E/etc/vmware/hostd/vmInventory.xml",
|
|
"product_version_evidence": [
|
|
"No explicit product/version fingerprint in nmap service line."
|
|
],
|
|
"exploit_precondition": "Target must expose VMware SDK endpoint (/sdk) and allow traversal into host files.",
|
|
"reproducibility": "not-reproduced",
|
|
"disposition": "needs-manual-test",
|
|
"disposition_rationale": "Script/banner evidence exists, but no direct proof of exploit impact was captured in scan output.",
|
|
"required_reproduction_step_before_ticket": "Before creating a ticket, reproduce vulnerable behavior directly (e.g., crafted request causing data exposure, traversal read, or exploitable crash) and attach request/response proof. Banner or script signature matches alone are insufficient.",
|
|
"evidence_sources": [
|
|
{
|
|
"file": "results/auth.lan.ddnsgeek.com/scans/_patterns.log",
|
|
"match_count": 3
|
|
},
|
|
{
|
|
"file": "results/auth.lan.ddnsgeek.com/scans/tcp443/tcp_443_https_nmap.txt",
|
|
"endpoint": "/sdk/../../../../../../../etc/vmware/hostd/vmInventory.xml",
|
|
"evidence": "Possible path traversal in VMWare (CVE-2009-3733)"
|
|
},
|
|
{
|
|
"file": "results/auth.lan.ddnsgeek.com/scans/tcp443/tcp_443_https_nmap.txt",
|
|
"endpoint": "/sdk/%2E%2E/%2E%2E/%2E%2E/%2E%2E/%2E%2E/%2E%2E/%2E%2E/etc/vmware/hostd/vmInventory.xml",
|
|
"evidence": "Possible path traversal in VMWare (CVE-2009-3733)"
|
|
}
|
|
]
|
|
},
|
|
{
|
|
"host": "auth.lan.ddnsgeek.com",
|
|
"cve": "CVE-2011-0966",
|
|
"affected_host": "auth.lan.ddnsgeek.com",
|
|
"endpoint": "/cwhp/auditLog.do?file=..\\..\\..\\..\\..\\..\\..\\Program%20Files\\CSCOpx\\MDC\\Tomcat\\webapps\\triveni\\WEB-INF\\classes\\schedule.properties",
|
|
"product_version_evidence": [
|
|
"No explicit product/version fingerprint in nmap service line."
|
|
],
|
|
"exploit_precondition": "Target must be Cisco Unified Operations Manager 8.0/8.5 with vulnerable auditLog.do traversal handling.",
|
|
"reproducibility": "not-reproduced",
|
|
"disposition": "needs-manual-test",
|
|
"disposition_rationale": "Script/banner evidence exists, but no direct proof of exploit impact was captured in scan output.",
|
|
"required_reproduction_step_before_ticket": "Before creating a ticket, reproduce vulnerable behavior directly (e.g., crafted request causing data exposure, traversal read, or exploitable crash) and attach request/response proof. Banner or script signature matches alone are insufficient.",
|
|
"evidence_sources": [
|
|
{
|
|
"file": "results/auth.lan.ddnsgeek.com/scans/_patterns.log",
|
|
"match_count": 4
|
|
},
|
|
{
|
|
"file": "results/auth.lan.ddnsgeek.com/scans/tcp443/tcp_443_https_nmap.txt",
|
|
"endpoint": "/cwhp/auditLog.do?file=..\\..\\..\\..\\..\\..\\..\\boot.ini",
|
|
"evidence": "Possible CiscoWorks (CuOM 8.0 and 8.5) Directory traversal (CVE-2011-0966) (Windows)"
|
|
},
|
|
{
|
|
"file": "results/auth.lan.ddnsgeek.com/scans/tcp443/tcp_443_https_nmap.txt",
|
|
"endpoint": "/cwhp/auditLog.do?file=..\\..\\..\\..\\..\\..\\..\\Program%20Files\\CSCOpx\\MDC\\Tomcat\\webapps\\triveni\\WEB-INF\\classes\\schedule.properties",
|
|
"evidence": "Possible CiscoWorks (CuOM 8.0 and 8.5) Directory traversal (CVE-2011-0966) (Windows)"
|
|
},
|
|
{
|
|
"file": "results/auth.lan.ddnsgeek.com/scans/tcp443/tcp_443_https_nmap.txt",
|
|
"endpoint": "/cwhp/auditLog.do?file=..\\..\\..\\..\\..\\..\\..\\Program%20Files\\CSCOpx\\lib\\classpath\\com\\cisco\\nm\\cmf\\dbservice2\\DBServer.properties",
|
|
"evidence": "Possible CiscoWorks (CuOM 8.0 and 8.5) Directory traversal (CVE-2011-0966) (Windows)"
|
|
},
|
|
{
|
|
"file": "results/auth.lan.ddnsgeek.com/scans/tcp443/tcp_443_https_nmap.txt",
|
|
"endpoint": "/cwhp/auditLog.do?file=..\\..\\..\\..\\..\\..\\..\\Program%20Files\\CSCOpx\\log\\dbpwdChange.log",
|
|
"evidence": "Possible CiscoWorks (CuOM 8.0 and 8.5) Directory traversal (CVE-2011-0966) (Windows)"
|
|
}
|
|
]
|
|
},
|
|
{
|
|
"host": "auth.lan.ddnsgeek.com",
|
|
"cve": "CVE-2018-10822",
|
|
"affected_host": "auth.lan.ddnsgeek.com",
|
|
"endpoint": "/uir//etc/passwd",
|
|
"product_version_evidence": [
|
|
"No explicit product/version fingerprint in nmap service line."
|
|
],
|
|
"exploit_precondition": "Target must be affected D-Link router firmware exposing /uir/ traversal path.",
|
|
"reproducibility": "not-reproduced",
|
|
"disposition": "needs-manual-test",
|
|
"disposition_rationale": "Script/banner evidence exists, but no direct proof of exploit impact was captured in scan output.",
|
|
"required_reproduction_step_before_ticket": "Before creating a ticket, reproduce vulnerable behavior directly (e.g., crafted request causing data exposure, traversal read, or exploitable crash) and attach request/response proof. Banner or script signature matches alone are insufficient.",
|
|
"evidence_sources": [
|
|
{
|
|
"file": "results/auth.lan.ddnsgeek.com/scans/_patterns.log",
|
|
"match_count": 1
|
|
},
|
|
{
|
|
"file": "results/auth.lan.ddnsgeek.com/scans/tcp443/tcp_443_https_nmap.txt",
|
|
"endpoint": "/uir//etc/passwd",
|
|
"evidence": "Possible D-Link router directory traversal vulnerability (CVE-2018-10822)"
|
|
}
|
|
]
|
|
},
|
|
{
|
|
"host": "auth.lan.ddnsgeek.com",
|
|
"cve": "CVE-2018-10824",
|
|
"affected_host": "auth.lan.ddnsgeek.com",
|
|
"endpoint": "/uir//tmp/csman/0",
|
|
"product_version_evidence": [
|
|
"No explicit product/version fingerprint in nmap service line."
|
|
],
|
|
"exploit_precondition": "Target must be affected D-Link router firmware exposing plaintext credential path under /tmp/csman.",
|
|
"reproducibility": "not-reproduced",
|
|
"disposition": "needs-manual-test",
|
|
"disposition_rationale": "Script/banner evidence exists, but no direct proof of exploit impact was captured in scan output.",
|
|
"required_reproduction_step_before_ticket": "Before creating a ticket, reproduce vulnerable behavior directly (e.g., crafted request causing data exposure, traversal read, or exploitable crash) and attach request/response proof. Banner or script signature matches alone are insufficient.",
|
|
"evidence_sources": [
|
|
{
|
|
"file": "results/auth.lan.ddnsgeek.com/scans/_patterns.log",
|
|
"match_count": 1
|
|
},
|
|
{
|
|
"file": "results/auth.lan.ddnsgeek.com/scans/tcp443/tcp_443_https_nmap.txt",
|
|
"endpoint": "/uir//tmp/csman/0",
|
|
"evidence": "Possible D-Link router plaintext password file exposure (CVE-2018-10824)"
|
|
}
|
|
]
|
|
},
|
|
{
|
|
"host": "auth.lan.ddnsgeek.com",
|
|
"cve": "CVE-2019-1653",
|
|
"affected_host": "auth.lan.ddnsgeek.com",
|
|
"endpoint": "/cgi-bin/config.exp",
|
|
"product_version_evidence": [
|
|
"No explicit product/version fingerprint in nmap service line."
|
|
],
|
|
"exploit_precondition": "Validate affected product/version and exploit path prerequisites before filing.",
|
|
"reproducibility": "not-reproduced",
|
|
"disposition": "needs-manual-test",
|
|
"disposition_rationale": "Script/banner evidence exists, but no direct proof of exploit impact was captured in scan output.",
|
|
"required_reproduction_step_before_ticket": "Before creating a ticket, reproduce vulnerable behavior directly (e.g., crafted request causing data exposure, traversal read, or exploitable crash) and attach request/response proof. Banner or script signature matches alone are insufficient.",
|
|
"evidence_sources": [
|
|
{
|
|
"file": "results/auth.lan.ddnsgeek.com/scans/_patterns.log",
|
|
"match_count": 2
|
|
},
|
|
{
|
|
"file": "results/auth.lan.ddnsgeek.com/scans/tcp443/tcp_443_https_nmap.txt",
|
|
"endpoint": "/cgi-bin/export_debug_msg.exp",
|
|
"evidence": "Cisco RV320/RV325 Unauthenticated Diagnostic Data & Configuration Export (CVE-2019-1653)"
|
|
},
|
|
{
|
|
"file": "results/auth.lan.ddnsgeek.com/scans/tcp443/tcp_443_https_nmap.txt",
|
|
"endpoint": "/cgi-bin/config.exp",
|
|
"evidence": "Cisco RV320/RV325 Unauthenticated Diagnostic Data & Configuration Export (CVE-2019-1653)"
|
|
}
|
|
]
|
|
}
|
|
]
|
|
}
|