15 lines
2.6 KiB
Markdown
15 lines
2.6 KiB
Markdown
# CVE triage sheet - prometheus.lan.ddnsgeek.com
|
|
|
|
Generated (UTC): 2026-04-07T03:49:38.723646+00:00
|
|
|
|
| CVE | Affected host | Endpoint | Product/version evidence | Exploit precondition | Reproducibility | Disposition |
|
|
|---|---|---|---|---|---|---|
|
|
| CVE-2009-3733 | prometheus.lan.ddnsgeek.com | `/sdk/%2E%2E/%2E%2E/%2E%2E/%2E%2E/%2E%2E/%2E%2E/%2E%2E/etc/vmware/hostd/vmInventory.xml` | No explicit product/version fingerprint in nmap service line. | Target must expose VMware SDK endpoint (/sdk) and allow traversal into host files. | not-reproduced | **not-applicable** |
|
|
| | | | | | | Required reproduction gate: Before creating a ticket, reproduce vulnerable behavior directly (e.g., crafted request causing data exposure, traversal read, or exploitable crash) and attach request/response proof. Banner or script signature matches alone are insufficient. |
|
|
| CVE-2011-0966 | prometheus.lan.ddnsgeek.com | `/cwhp/auditLog.do?file=..\..\..\..\..\..\..\Program%20Files\CSCOpx\MDC\Tomcat\webapps\triveni\WEB-INF\classes\schedule.properties` | No explicit product/version fingerprint in nmap service line. | Target must be Cisco Unified Operations Manager 8.0/8.5 with vulnerable auditLog.do traversal handling. | not-reproduced | **not-applicable** |
|
|
| | | | | | | Required reproduction gate: Before creating a ticket, reproduce vulnerable behavior directly (e.g., crafted request causing data exposure, traversal read, or exploitable crash) and attach request/response proof. Banner or script signature matches alone are insufficient. |
|
|
| CVE-2018-10822 | prometheus.lan.ddnsgeek.com | `/uir//etc/passwd` | No explicit product/version fingerprint in nmap service line. | Target must be affected D-Link router firmware exposing /uir/ traversal path. | not-reproduced | **not-applicable** |
|
|
| | | | | | | Required reproduction gate: Before creating a ticket, reproduce vulnerable behavior directly (e.g., crafted request causing data exposure, traversal read, or exploitable crash) and attach request/response proof. Banner or script signature matches alone are insufficient. |
|
|
| CVE-2018-10824 | prometheus.lan.ddnsgeek.com | `/uir//tmp/csman/0` | No explicit product/version fingerprint in nmap service line. | Target must be affected D-Link router firmware exposing plaintext credential path under /tmp/csman. | not-reproduced | **not-applicable** |
|
|
| | | | | | | Required reproduction gate: Before creating a ticket, reproduce vulnerable behavior directly (e.g., crafted request causing data exposure, traversal read, or exploitable crash) and attach request/response proof. Banner or script signature matches alone are insufficient. |
|