Files
autorecon/results/auth.lan.ddnsgeek.com/scans/_cve_triage.md
T

1.4 KiB

CVE triage sheet - auth.lan.ddnsgeek.com

Generated (UTC): 2026-04-07T03:49:38.723646+00:00

CVE Affected host Endpoint Product/version evidence Exploit precondition Reproducibility Disposition
CVE-2005-3299 auth.lan.ddnsgeek.com 443/tcp ssl/http syn-ack ttl 55 Golang net/http server (Go-IPFS json-rpc or InfluxDB API) Target must run Apache 2.0.x with mod_imap module enabled and vulnerable to cross-site scripting behavior. not-reproduced needs-manual-test
Required reproduction gate: Before creating a ticket, reproduce vulnerable behavior directly (e.g., crafted request causing data exposure, traversal read, or exploitable crash) and attach request/response proof. Banner or script signature matches alone are insufficient.
CVE-2009-3733 auth.lan.ddnsgeek.com /sdk/%2E%2E/%2E%2E/%2E%2E/%2E%2E/%2E%2E/%2E%2E/%2E%2E/etc/vmware/hostd/vmInventory.xml No explicit product/version fingerprint in nmap service line. Target must expose VMware SDK endpoint (/sdk) and allow traversal into host files. not-reproduced needs-manual-test
Required reproduction gate: Before creating a ticket, reproduce vulnerable behavior directly (e.g., crafted request causing data exposure, traversal read, or exploitable crash) and attach request/response proof. Banner or script signature matches alone are insufficient.