www.commerce.ohal.vn có an toàn không? Điểm bảo mật 62/100 | CyStack
www.commerce.ohal.vn
Cửa hàng - OHAL
Liên hệ với chúng tôi để được tư vấn về sản phẩm, dịch vụ hoặc những thông tin về chăm sóc sức khoẻ. Cập nhật các chính sách mới nhất.
Lĩnh vực
–
Nguồn gốc
Việt Nam
Xếp hạng toàn cầu
#6.978.435
Xếp hạng tại Việt Nam
#133.234
Cập nhật lúc
D62/100
Mức an toàn
Cần cải thiện
Độ tin cậy dữ liệu
Cao
Phạm vi đã kiểm tra
94,5%
Điểm càng cao, hệ thống càng ghi nhận được nhiều biện pháp bảo vệ quan sát từ bên ngoài. Trang này không nhằm chứng nhận website uy tín, hợp pháp hay hoàn toàn không có lỗ hổng.
Trang web “www.commerce.ohal.vn” có an toàn không?
Tính đến 06:13 ngày 18/9/2026, www.commerce.ohal.vn đạt 62/100 điểm an toàn (đạt hạng D: “Cần cải thiện”). Hệ thống quét tự động của CyStack ghi nhận 18 vấn đề cần xem xét sau khi kiểm tra 94,5% hạng mục. Chủ sở hữu website nên ưu tiên khắc phục “Mức độ công khai của dịch vụ quản trị”, sau đó rà soát các mục còn lại theo mức độ ảnh hưởng.
Có dấu hiệu lừa đảo, phishing hoặc mã độc nào liên quan đến www.commerce.ohal.vn không?
CyStack chưa ghi nhận www.commerce.ohal.vn hay hạ tầng liên quan trong bất kỳ danh sách cảnh báo lừa đảo, phishing hoặc mã độc nào tại thời điểm quét, sau khi đối chiếu 5 nguồn danh tiếng trực tuyến. Kết quả này phản ánh quan sát từ bên ngoài, không đảm bảo website an toàn tuyệt đối và không xác nhận tư cách pháp lý hay uy tín của tổ chức.
Điều gì đang ảnh hưởng đến độ an toàn của www.commerce.ohal.vn?
Chứng thư SSL hợp lệ vẫn chưa đủ để khẳng định www.commerce.ohal.vn là website an toàn, uy tín hay không có dấu hiệu lừa đảo. Để đánh giá toàn diện hơn, báo cáo còn kiểm tra phishing và mã độc, email lộ lọt, IP và cổng mở, tên miền phụ, công nghệ cùng các CVE có thể liên quan đến phiên bản ghi nhận được.
www.commerce.ohal.vn có dùng HTTPS và chứng thư SSL còn hợp lệ không?
www.commerce.ohal.vn đang dùng chứng thư SSL hợp lệ tại thời điểm đánh giá, có hiệu lực đến ngày 2 tháng 11, 2026. Trạng thái này có thể thay đổi khi chứng thư hết hạn hoặc máy chủ đổi cấu hình.
Dữ liệu được tổng hợp từ các hệ thống giám sát an ninh mạng của CyStack
CyStack tổng hợp kết quả quét từ các hệ thống giám sát an ninh mạng nội bộ, bao gồm CyStack VulnScan và CyStack Threat Intelligence, cùng các nguồn dữ liệu công khai trên Internet. Quá trình đánh giá chỉ quan sát và phân tích thông tin sẵn có, không đăng nhập trái phép, thử mật khẩu, gửi mã khai thác hay làm thay đổi, gián đoạn hệ thống được đánh giá.
Có 3 tiêu chí không đạt hoặc cảnh báo có ảnh hưởng lớn nhất tới kết quả của www.commerce.ohal.vn.
Mức độ công khai của dịch vụ quản trịPhát hiện dịch vụ quản trị công khai đã được xác nhận qua phản hồi dịch vụ: 123.30.136.200:22 (ssh).Cao
Vì sao cần quan tâm
Dịch vụ quản trị từ xa như RDP, VNC, Docker, Kubernetes và bảng điều khiển là mục tiêu có giá trị cao. Khi mở công khai, bất kỳ ai trên Internet cũng có thể thử mật khẩu hoặc khai thác dịch vụ chưa được vá.
Nên làm gì
Loại bỏ truy cập trực tiếp từ Internet và yêu cầu VPN, cổng truy cập được bảo vệ chặt hoặc mạng nguồn tin cậy; đồng thời bật MFA khi dịch vụ hỗ trợ.
Bằng chứng và phạm vi kiểm tra
Hoàn tất:
Có
Các cổng đã kiểm tra:
21, 22, 23, 25, 53, 80, 110, 111, 139, 143… và 48 giá trị khác
Dịch vụ mở phù hợp:
123.30.136.200:22, ssh OpenSSH 8.7
Số dịch vụ được chọn để nhận diện:
15
Số dịch vụ đã nhận diện:
14
Đã hoàn tất nhận diện dịch vụ:
Không
Cơ sở dữ liệu hoặc cache mở ra InternetPhát hiện dịch vụ kho dữ liệu công khai đã được xác nhận qua phản hồi dịch vụ: 123.30.136.200:3306 (mysql).Cao
Vì sao cần quan tâm
Cơ sở dữ liệu và cache thường chứa thông tin nhạy cảm và chỉ được ứng dụng nội bộ sử dụng. Truy cập trực tiếp từ Internet khiến tấn công mật khẩu hoặc lỗi cấu hình dễ dẫn tới lộ dữ liệu hơn.
Nên làm gì
Chỉ lắng nghe trên giao diện mạng riêng, chỉ cho phép các hệ thống ứng dụng cần thiết kết nối và yêu cầu xác thực mạnh cùng mã hóa.
Dịch vụ cũ không mã hóaPhát hiện dịch vụ plaintext lỗi thời công khai đã được xác nhận qua phản hồi dịch vụ: 123.30.136.200:21 (ftp), 123.30.136.200:110 (pop3), 123.30.136.200:143 (imap).Cao
Vì sao cần quan tâm
Các dịch vụ cũ như Telnet, FTP và giao thức email hoặc thư mục không mã hóa có thể gửi mật khẩu, dữ liệu ở dạng đọc được. Bên quan sát đường truyền có thể thu thập các thông tin này.
Nên làm gì
Tắt dịch vụ cũ hoặc thay bằng lựa chọn có mã hóa như SSH, SFTP, HTTPS hay phiên bản bảo mật của giao thức email.
Mỗi địa chỉ IP công khai được nhóm cùng dịch vụ đang mở, sản phẩm đã nhận diện và các CVE có khả năng liên quan đến phiên bản quan sát được.
Đã hoàn tất kiểm thử 58 cổng TCP
123.30.136.200c123200.vinahost.org
15 dịch vụ đang mở20 sản phẩm đã nhận diện
Nhà cung cấp hạ tầng hoặc mạngChưa xác định được nhà cung cấp
Vị trí mạng–
ASN–
21FtpPure Ftpd
Sản phẩmPhiên bảnLỗ hổng có thể liên quan
Pure FtpdChưa thấy phiên bản
Công nghệ khác quan sát được ở cấp websiteCác sản phẩm này được quan sát từ website công khai, nhưng chưa có đủ bằng chứng để gắn an toàn với một địa chỉ IP và cổng cụ thể.
DovecotChưa thấy phiên bảnChưa thấy phiên bản
Độ tin cậyThấp
Email @ohal.vn có xuất hiện trong dữ liệu lộ lọt hoặc nhật ký của phần mềm đánh cắp thông tin (infostealer) không?
Chưa tìm thấy bản ghi gắn với địa chỉ email @ohal.vn trong dữ liệu hiện có. Kết quả này không loại trừ những sự cố chưa được ghi nhận.
www.commerce.ohal.vn đang công khai những IP, dịch vụ và cổng nào?
Ghi nhận được 1 IP công khai và 15 cổng đang mở của www.commerce.ohal.vn. Cổng mở không tương đương với việc có lỗ hổng, nhưng chủ sở hữu website nên cập nhật thường xuyên và giới hạn truy cập cho từng dịch vụ công khai.
Đã phát hiện được bao nhiêu tên miền phụ của ohal.vn?
Ghi nhận 6 tên miền phụ công khai của ohal.vn. Danh sách này giúp nhận biết thêm các cổng vào như API, hệ thống quản trị hay môi trường thử nghiệm, nhưng không có nghĩa tên miền phụ nào cũng có rủi ro.
Định danh CPEcpe:2.3:a:pureftpd:pure-ftpd:*:*:*:*:*:*:*:*
Độ tin cậyTrung bình
22SshOpenssh24 CVE có thể liên quan
Sản phẩmPhiên bảnLỗ hổng có thể liên quan
Openssh8.78.724 CVE có thể liên quanCVSS 9,8
Định danh CPEcpe:2.3:a:openbsd:openssh:8.7:*:*:*:*:*:*:*
Độ tin cậyCao
CVE tiềm năng của sản phẩm này
CVE-2023-38408OpenSSH 8.7CVSS 9,8
Sản phẩm đối chiếu: OpenSSH 8.7 Độ tin cậy: Cao
The PKCS#11 feature in ssh-agent in OpenSSH before 9.3p2 has an insufficiently trustworthy search path, leading to remote code execution if an agent is forwarded to an attacker-controlled system. (Code in /usr/lib is not necessarily safe for loading into ssh-agent.) NOTE: this issue exists because of an incomplete fix for CVE-2016-10009.
Định danh CPEcpe:2.3:a:powerdns:authoritative_server:4.9.5:*:*:*:*:*:*:*
Độ tin cậyCao
80HTTPLiteSpeed Web Server
Sản phẩmPhiên bảnLỗ hổng có thể liên quan
LiteSpeed Web ServerChưa thấy phiên bảnChưa thấy phiên bản
Độ tin cậyThấp
110Pop3Dovecot
Sản phẩmPhiên bảnLỗ hổng có thể liên quan
DovecotChưa thấy phiên bảnChưa thấy phiên bản
Độ tin cậyThấp
111RpcChưa nhận diện được sản phẩm
Chưa nhận diện được sản phẩm
143ImapChưa nhận diện được sản phẩm
Chưa nhận diện được sản phẩm
443HTTPĐã xác minh TLSPHPElementorExpress+1114 CVE có thể liên quan
Sản phẩmPhiên bảnLỗ hổng có thể liên quan
PHP8.3.27Programming Languages8.3.2714 CVE có thể liên quanCVSS 9,8
Định danh CPEcpe:2.3:a:php:php:*:*:*:*:*:*:*:*
Độ tin cậyTrung bình
PHP is a general-purpose scripting language used for web development.
465SmtpĐã xác minh TLSExim9 CVE có thể liên quan
Sản phẩmPhiên bảnLỗ hổng có thể liên quan
Exim4.994.999 CVE có thể liên quanCVSS 9,8
Định danh CPEcpe:2.3:a:exim:exim:4.99:*:*:*:*:*:*:*
Độ tin cậyCao
CVE tiềm năng của sản phẩm này
CVE-2025-67896Exim 4.99CVSS 9,8
Sản phẩm đối chiếu: Exim 4.99 Độ tin cậy: Cao
Exim before 4.99.1, with certain non-default rate-limit configurations, allows a remote heap-based buffer overflow because database records are cast directly to internal structures without validation.
Định danh CPEcpe:2.3:a:exim:exim:4.99:*:*:*:*:*:*:*
Độ tin cậyCao
CVE tiềm năng của sản phẩm này
CVE-2025-67896Exim 4.99CVSS 9,8
Sản phẩm đối chiếu: Exim 4.99 Độ tin cậy: Cao
Exim before 4.99.1, with certain non-default rate-limit configurations, allows a remote heap-based buffer overflow because database records are cast directly to internal structures without validation.
993ImapsĐã xác minh TLSChưa nhận diện được sản phẩm
Chưa nhận diện được sản phẩm
995Pop3Đã xác minh TLSDovecot
Sản phẩmPhiên bảnLỗ hổng có thể liên quan
DovecotChưa thấy phiên bảnChưa thấy phiên bản
Độ tin cậyThấp
3000HTTPExpressNode Js
Sản phẩmPhiên bảnLỗ hổng có thể liên quan
ExpressChưa thấy phiên bảnWeb Frameworks · Web ServersChưa thấy phiên bản
Định danh CPEcpe:2.3:a:expressjs:express:*:*:*:*:*:*:*:*
Độ tin cậyTrung bình
Express is a web application framework for Node.js, released as free and open-source software under the MIT License. It is designed for building web applications and APIs.
Mariadb10.11.1410.11.149 CVE có thể liên quanCVSS 9,8
Định danh CPEcpe:2.3:a:mariadb:mariadb:10.11.14:*:*:*:*:*:*:*
Độ tin cậyCao
CVE tiềm năng của sản phẩm này
CVE-2026-44170MariaDB 10.11.14CVSS 9,8
Sản phẩm đối chiếu: MariaDB 10.11.14 Độ tin cậy: Cao
MariaDB server is a community developed fork of MySQL server. From versions 10.6.1 to before 10.6.26, 10.11.1 to before 10.11.17, 11.4.1 to before 11.4.11, 11.8.1 to before 11.8.7, and 12.3.1, MariaDB on WIndows with installed CONNECT engine and enabled REST support interpolated table HTTP attribute into the curl command line without proper sanitizing. This allows the user to execute shell commands on the server. This issue has been patched in versions 10.6.26, 10.11.17, 11.4.11, 11.8.7, and 12.3.2.
ssh in OpenSSH before 10.4 can have a use-after-free when a server changes its host key during a key re-exchange. (This outcome occurs only on the client side.)
A security regression (CVE-2006-5051) was discovered in OpenSSH's server (sshd). There is a race condition which can lead sshd to handle some signals in an unsafe manner. An unauthenticated, remote attacker may be able to trigger it by failing to authenticate within a set time period.
In OpenSSH before 10.3, a file downloaded by scp may be installed setuid or setgid, an outcome contrary to some users' expectations, if the download is performed as root with -O (legacy scp protocol) and without -p (preserve mode).
OpenSSH before 10.3 mishandles the authorized_keys principals option in uncommon scenarios involving a principals list in conjunction with a Certificate Authority that makes certain use of comma characters.
sshd in OpenSSH before 10.4 allows remote attackers to cause a denial of service (resource consumption from excessive authentication attempts) because MaxAuthTries was mishandled for GSSAPIAuthentication.
sshd in OpenSSH 6.2 through 8.x before 8.8, when certain non-default configurations are used, allows privilege escalation because supplemental groups are not initialized as expected. Helper programs for AuthorizedKeysCommand and AuthorizedPrincipalsCommand may run with privileges associated with group memberships of the sshd process, if the configuration specifies running the command as a different user.
A vulnerability was found in OpenSSH when the VerifyHostKeyDNS option is enabled. A machine-in-the-middle attack can be performed by a malicious machine impersonating a legit server. This issue occurs due to how OpenSSH mishandles error codes in specific conditions when verifying the host key. For an attack to be considered successful, the attacker needs to manage to exhaust the client's memory resource first, turning the attack complexity high.
In ssh in OpenSSH before 9.6, OS command injection might occur if a user name or host name has shell metacharacters, and this name is referenced by an expansion token in certain situations. For example, an untrusted Git repository can have a submodule with shell metacharacters in a user name or host name.
OpenSSH before 10.3 can use unintended ECDSA algorithms. Listing of any ECDSA algorithm in PubkeyAcceptedAlgorithms or HostbasedAcceptedAlgorithms is misinterpreted to mean all ECDSA algorithms.
sshd in OpenSSH before 10.4 has an undocumented security-relevant behavior: GSSAPIStrictAcceptorCheck has no value if the server is in Windows Active Directory.
The SSH transport protocol with certain OpenSSH extensions, found in OpenSSH before 9.6 and other products, allows remote attackers to bypass integrity checks such that some packets are omitted (from the extension negotiation message), and a client and server may consequently end up with a connection for which some security features have been downgraded or disabled, aka a Terrapin attack. This occurs because the SSH Binary Packet Protocol (BPP), implemented by these extensions, mishandles the handshake phase and mishandles use of sequence numbers. For example, there is an effective attack against SSH's use of ChaCha20-Poly1305 (and CBC with Encrypt-then-MAC). The bypass occurs in chacha20-poly1305@openssh.com and (if CBC is used) the -etm@openssh.com MAC algorithms. This also affects Maverick Synergy Java SSH API before 3.1.0-SNAPSHOT, Dropbear through 2022.83, Ssh before 5.1.1 in Erlang/OTP, PuTTY before 0.80, AsyncSSH before 2.14.2, golang.org/x/crypto before 0.17.0, libssh before 0.10.6, libssh2 through 1.11.0, Thorn Tech SFTP Gateway before 3.4.6, Tera Term before 5.1, Paramiko before 3.4.0, jsch before 0.2.15, SFTPGo before 2.5.6, Netgate pfSense Plus through 23.09.1, Netgate pfSense CE through 2.7.2, HPN-SSH through 18.2.0, ProFTPD before 1.3.8b (and before 1.3.9rc2), ORYX CycloneSSH before 2.3.4, NetSarang XShell 7 before Build 0144, CrushFTP before 10.6.0, ConnectBot SSH library before 2.2.22, Apache MINA sshd through 2.11.0, sshj through 0.37.0, TinySSH through 20230101, trilead-ssh2 6401, LANCOM LCOS and LANconfig, FileZilla before 3.66.4, Nova before 11.8, PKIX-SSH before 14.4, SecureCRT before 9.4.3, Transmit5 before 5.10.4, Win32-OpenSSH before 9.5.0.0p1-Beta, WinSCP before 6.2.2, Bitvise SSH Server before 9.32, Bitvise SSH Client before 9.33, KiTTY through 0.76.1.13, the net-ssh gem 7.2.0 for Ruby, the mscdex ssh2 module before 1.15.0 for Node.js, the thrussh library before 0.35.1 for Rust, and the Russh crate before 0.40.2 for Rust.
sftp in OpenSSH before 10.4 does not properly constrain the location of downloaded files when "sftp server:/path ." is used with an attacker-controlled server.
internal-sftp in sshd in OpenSSH before 10.4 recognizes only the first 9 command-line arguments, which can be important if a later command-line argument would have helped to ensure the intended security properties of an SFTP connection.
OpenSSH through 8.7 allows remote attackers, who have a suspicion that a certain combination of username and public key is known to an SSH server, to test whether this suspicion is correct. This occurs because a challenge is sent only when that combination could be valid for a login session. NOTE: the vendor does not recognize user enumeration as a vulnerability for this product
In sshd in OpenSSH before 10.0, the DisableForwarding directive does not adhere to the documentation stating that it disables X11 and agent forwarding.
An issue was discovered in OpenSSH before 8.9. If a client is using public-key authentication with agent forwarding but without -oLogLevel=verbose, and an attacker has silently modified the server to support the None authentication option, then the user cannot determine whether FIDO authentication is going to confirm that the user wishes to connect to that server, or that the user wishes to allow that server to connect to a different server on the user's behalf. NOTE: the vendor's position is "this is not an authentication bypass, since nothing is being bypassed.
In ssh-agent in OpenSSH before 10.5, some operations can occur remotely but were intended to occur only locally, including operations that add tokens or use keys. This is caused by misinteraction between agent locking and the session-bind@openssh.com extension.
Sản phẩm đối chiếu: PHP 8.3.27 Độ tin cậy: Trung bình
In PHP versions 8.2.* before 8.2.31, 8.3.* before 8.3.31, 8.4.* before 8.4.21, and 8.5.* before 8.5.6, the PDO Firebird driver improperly handles NUL bytes when preparing SQL queries. During token-by-token query construction, a string token containing a NUL byte is copied via strncat(), which stops at the NUL byte, dropping the closing quote and causing subsequent SQL tokens to be interpreted as part of the string. This allows SQL injection when attacker-controlled values are quoted via PDO::quote() and embedded in SQL statements.
Sản phẩm đối chiếu: PHP 8.3.27 Độ tin cậy: Trung bình
Improper escaping of backslashes in attacker-provided parameters would allow for trivial SQL injection in PHP versions from 8.2.* before 8.2.33, from 8.3.* before 8.3.33, from 8.4.* before 8.4.24, and from 8.5.* before 8.5.9.
Sản phẩm đối chiếu: PHP 8.3.27 Độ tin cậy: Trung bình
In PHP versions 8.2.* before 8.2.31, 8.3.* before 8.3.31, 8.4.* before 8.4.21, and 8.5.* before 8.5.6, the SOAP extension's object deduplication mechanism stores pointers to PHP objects in a global map without incrementing their reference counts. When an apache:Map node contains duplicate keys, processing the second entry overwrites the first in the temporary result map, freeing the original PHP object while its stale pointer remains in the map. A subsequent href reference to the freed node can copy the dangling pointer into the result. As PHP string allocations can reclaim the freed memory region, an attacker with control over the SOAP request body can exploit this use-after-free to achieve remote code execution.
Sản phẩm đối chiếu: PHP 8.3.27 Độ tin cậy: Trung bình
In PHP versions 8.2.* before 8.2.31, 8.3.* before 8.3.31, 8.4.* before 8.4.21, and 8.5.* before 8.5.6, when SoapServer is configured with SOAP_PERSISTENCE_SESSION, the handler object is persisted across requests via session storage. However, in the case SOAP requests results in an error, the persistance is handled incorrectly, resulting in freeing the object while keeping a pointer to it, which may lead to use-after-free. This may lead to memory corruption, information disclosure, or process crashes, with confidentiality, integrity, and availability impact on the vulnerable system.
Sản phẩm đối chiếu: PHP 8.3.27 Độ tin cậy: Trung bình
In PHP versions:8.1.* before 8.1.34, 8.2.* before 8.2.30, 8.3.* before 8.3.29, 8.4.* before 8.4.16, 8.5.* before 8.5.1, a heap buffer overflow occurs in array_merge() when the total element count of packed arrays exceeds 32-bit limits or HT_MAX_SIZE, due to an integer overflow in the precomputation of element counts using zend_hash_num_elements(). This may lead to memory corruption or crashes and affect the integrity and availability of the target server.
Sản phẩm đối chiếu: PHP 8.3.27 Độ tin cậy: Trung bình
In PHP versions:8.1.* before 8.1.34, 8.2.* before 8.2.30, 8.3.* before 8.3.29, 8.4.* before 8.4.16, 8.5.* before 8.5.1, the getimagesize() function may leak uninitialized heap memory into the APPn segments (e.g., APP1) when reading images in multi-chunk mode (such as via php://filter). This occurs due to a bug in php_read_stream_all_chunks() that overwrites the buffer without advancing the pointer, leaving tail bytes uninitialized. This may lead to information disclosure of sensitive heap data and affect the confidentiality of the target server.
Sản phẩm đối chiếu: PHP 8.3.27 Độ tin cậy: Trung bình
In PHP versions 8.1.* before 8.1.34, 8.2.* before 8.2.30, 8.3.* before 8.3.29, 8.4.* before 8.4.16, 8.5.* before 8.5.1 when using the PDO PostgreSQL driver with PDO::ATTR_EMULATE_PREPARES enabled, an invalid character sequence (such as \x99) in a prepared statement parameter may cause the quoting function PQescapeStringConn to return NULL, leading to a null pointer dereference in pdo_parse_params() function. This may lead to crashes (segmentation fault) and affect the availability of the target server.
Sản phẩm đối chiếu: PHP 8.3.27 Độ tin cậy: Trung bình
In PHP versions 8.2.* before 8.2.31, 8.3.* before 8.3.31, 8.4.* before 8.4.21, and 8.5.* before 8.5.6, some functions, including urldecode(), pass signed char to ctype functions (like isxdigit()). On the systems with default signed char and optimized table-lookup ctype functions - such as NetBSD - this can lead to accessing array with negative offset, which can trigger a denial of service.
Sản phẩm đối chiếu: PHP 8.3.27 Độ tin cậy: Trung bình
In PHP versions 8.2.* before 8.2.31, 8.3.* before 8.3.31, 8.4.* before 8.4.21, and 8.5.* before 8.5.6, when a SOAP server has a typemap configured, the decoding process contains a mistake which checks the wrong variable in case of missing value element. This leads to dereferences a NULL pointer, causing a segmentation fault. This allows a remote unauthenticated attacker to crash the PHP SOAP server process, resulting in denial of service.
Sản phẩm đối chiếu: PHP 8.3.27 Độ tin cậy: Trung bình
In PHP versions 8.2.* before 8.2.31, 8.3.* before 8.3.31, 8.4.* before 8.4.21, and 8.5.* before 8.5.6, the metaphone() function in ext/standard/metaphone.c uses a signed int variable to track the current position within the input string. If a string longer than 2,147,483,647 bytes is passed, a signed integer overflow occurs, resulting in undefined behavior. This can lead to an out-of-bounds read, causing a segmentation fault or access to unrelated memory, and may affect the availability of the PHP process.
Sản phẩm đối chiếu: PHP 8.3.27 Độ tin cậy: Trung bình
In PHP versions 8.2.* before 8.2.31, 8.3.* before 8.3.31, 8.4.* before 8.4.21, and 8.5.* before 8.5.6, a mismatch between encoding lists in Oniguruma and mbfl leads to a NULL pointer dereference, resulting in a segmentation fault and denial of service. The vulnerability is exploitable when user-controlled input can influence the encoding passed to mb_regex_encoding().
Sản phẩm đối chiếu: PHP 8.3.27 Độ tin cậy: Trung bình
In PHP versions 8.2.* before 8.2.31, 8.3.* before 8.3.31, 8.4.* before 8.4.21, 8.5.* before 8.5.6, due to improper sanitation of user data, it allows an attacker to compose an URL, which will cause the target to execute arbitrary JavaScript code (XSS) on the target's machine when the target is viewing the PHP-FPM status page.
Sản phẩm đối chiếu: PHP 8.3.27 Độ tin cậy: Trung bình
Circular symbolic links in phar archives could lead to unbounded recursion, exhausting the C stack and crashing the PHP process, in PHP versions from 8.2.* before 8.2.33, from 8.3.* before 8.3.33, from 8.4.* before 8.4.24, and from 8.5.* before 8.5.9.
Sản phẩm đối chiếu: PHP 8.3.27 Độ tin cậy: Trung bình
In PHP versions 8.2.* before 8.2.32, 8.3.* before 8.3.32, 8.4.* before 8.4.23, 8.5.* before 8.5.8, the AES-WRAP-PAD algorithm implementation in OpenSSL extension contains a buffer allocation flaw. The output buffer for the AES key-wrap-with-padding operation is sized from the plaintext length without accounting for RFC 5649 expansion. This may cause OpenSSL to write beyond allocated memory, corrupting heap metadata and triggering application abort.
ExpressChưa thấy phiên bảnWeb Frameworks · Web ServersChưa thấy phiên bản
Định danh CPEcpe:2.3:a:expressjs:express:*:*:*:*:*:*:*:*
Độ tin cậyTrung bình
Express is a web application framework for Node.js, released as free and open-source software under the MIT License. It is designed for building web applications and APIs.
jQueryChưa thấy phiên bảnJavaScript LibrariesChưa thấy phiên bản
Định danh CPEcpe:2.3:a:jquery:jquery:*:*:*:*:*:*:*:*
Độ tin cậyTrung bình
jQuery is a JavaScript library which is a free, open-source software designed to simplify HTML DOM tree traversal and manipulation, as well as event handling, CSS animation, and Ajax.
jQuery MigrateChưa thấy phiên bảnJavaScript LibrariesChưa thấy phiên bản
Độ tin cậyTrung bình
Query Migrate is a javascript library that allows you to preserve the compatibility of your jQuery code developed for versions of jQuery older than 1.9.
Định danh CPEcpe:2.3:a:wordpress:wordpress:*:*:*:*:*:*:*:*
Độ tin cậyTrung bình
WordPress is a free and open-source content management system written in PHP and paired with a MySQL or MariaDB database. Features include a plugin architecture and a template system.
In Exim before 4.99.2, when JSON lookup is enabled, an out-of-bounds heap write can occur when a JSON operator encounters malformed JSON in an untrusted header, because of an incorrect implementation of \ skipping.
Exim before 4.99.3, in certain GnuTLS configurations, has a remotely reachable use-after-free in the BDAT body parsing path. It is triggered when a client sends a TLS close_notify mid-body during a CHUNKING transfer, followed by a final cleartext byte on the same TCP connection. This can lead to heap corruption. An unauthenticated network attacker exploiting this vulnerability could execute arbitrary code.
In Exim before 4.99.2, when the SPA authentication driver is used with an adversarial SPA resource, there can be an out-of-bounds write that crashes the connection instance, or erroneous data processing that divulges data from uninitialized heap memory.
Exim before 4.99.5 allows directory traversal to access files outside of the spool area, and consequently gain privileges, because arguments related to queue-name are mishandled.
In Exim before 4.99.2, on systems using musl libc (not glibc), an attacker can crash the connection instance when malformed DNS data is present in PTR records. This is caused by a dn_expand oddity in octal printing.
In Exim before 4.99.2, when utf8 operators are enabled, there is an out-of-bounds read if large UTF-8 trailing characters are present (malformed UTF-8 header data). Information might be divulged within an error message produced during handling of an unrelated e-mail message.
Exim 4.88 before 4.99.4, in some proxy configurations, mishandles certain short payloads, leading to disclosure of uninitialized stack memory values to a client.
In Exim before 4.99.2, when JSON lookup is enabled, an out-of-bounds heap write can occur when a JSON operator encounters malformed JSON in an untrusted header, because of an incorrect implementation of \ skipping.
Exim before 4.99.3, in certain GnuTLS configurations, has a remotely reachable use-after-free in the BDAT body parsing path. It is triggered when a client sends a TLS close_notify mid-body during a CHUNKING transfer, followed by a final cleartext byte on the same TCP connection. This can lead to heap corruption. An unauthenticated network attacker exploiting this vulnerability could execute arbitrary code.
In Exim before 4.99.2, when the SPA authentication driver is used with an adversarial SPA resource, there can be an out-of-bounds write that crashes the connection instance, or erroneous data processing that divulges data from uninitialized heap memory.
Exim before 4.99.5 allows directory traversal to access files outside of the spool area, and consequently gain privileges, because arguments related to queue-name are mishandled.
In Exim before 4.99.2, on systems using musl libc (not glibc), an attacker can crash the connection instance when malformed DNS data is present in PTR records. This is caused by a dn_expand oddity in octal printing.
In Exim before 4.99.2, when utf8 operators are enabled, there is an out-of-bounds read if large UTF-8 trailing characters are present (malformed UTF-8 header data). Information might be divulged within an error message produced during handling of an unrelated e-mail message.
Exim 4.88 before 4.99.4, in some proxy configurations, mishandles certain short payloads, leading to disclosure of uninitialized stack memory values to a client.
Sản phẩm đối chiếu: MariaDB 10.11.14 Độ tin cậy: Cao
MariaDB server is a community developed fork of MySQL server. Versions 10.6.1 through 10.6.26, 10.11.1 through 10.11.17, 11.4.1 through 11.4.11, 11.8.1 through 11.8.7, and 12.3.1 with `wsrep_notify_cmd` enabled would execute shell commands embedded in the name of the joiner node. This is fixed in 10.6.27, 10.11.18, 11.4.12, 11.8.8, and 12.3.2. As a workaround, anyone who cannot upgrade now should disable `wsrep_notify_cmd`.
Sản phẩm đối chiếu: MariaDB 10.11.14 Độ tin cậy: Cao
MariaDB server is a community developed fork of MySQL server. From versions 10.6.1 to before 10.6.26, 10.11.1 to before 10.11.17, 11.4.1 to before 11.4.11, 11.8.1 to before 11.8.7, and 12.3.1, during the SST the donor node is interpolating parameters that the joiner sent into the command line. Not all parameters were properly validated which could allow a malicious joiner to execute arbitrary shell commands on the donor side via the mariabackup SST method. This issue has been patched in versions 10.6.26, 10.11.17, 11.4.11, 11.8.7, and 12.3.2.
Sản phẩm đối chiếu: MariaDB 10.11.14 Độ tin cậy: Cao
MariaDB server is a community developed fork of MySQL server. From versions 10.6.1 to before 10.6.26, 10.11.1 to before 10.11.17, 11.4.1 to before 11.4.11, 11.8.1 to before 11.8.7, and 12.3.1, mbstream did not check for /../ in the path when unpacking the archive. A proper backup can never contain such paths, but a specially crafted archive could have caused mbstream to create files outside of the target-dir path. This issue has been patched in versions 10.6.26, 10.11.17, 11.4.11, 11.8.7, and 12.3.2.
Sản phẩm đối chiếu: MariaDB 10.11.14 Độ tin cậy: Cao
MariaDB server is a community developed fork of MySQL server. From versions 10.6.1 to before 10.6.27, 10.11.1 to before 10.11.18, 11.4.1 to before 11.4.12, 11.8.1 to before 11.8.8, and 12.3.1, during the SST the donor node is interpolating parameters that the joiner sent into the command line. Not all parameters were properly validated which could allow a malicious joiner to execute arbitrary shell commands on the donor side via the rsync SST method. This issue has been patched in versions 10.6.27, 10.11.18, 11.4.12, 11.8.8, and 12.3.2.
Sản phẩm đối chiếu: MariaDB 10.11.14 Độ tin cậy: Cao
MariaDB server is a community developed fork of MySQL server. From versions 10.6.1 to before 10.6.27, 10.11.1 to before 10.11.18, 11.4.1 to before 11.4.12, 11.8.1 to before 11.8.8, and 12.3.1, a high-privileged MariaDB user could've used wsrep_sst_receive_address or wsrep_sst_donor global system variables to execute shell commands as the uid of the mariadbd process on the galera joiner node. This issue has been patched in versions 10.6.27, 10.11.18, 11.4.12, 11.8.8, and 12.3.2.
Sản phẩm đối chiếu: MariaDB 10.11.14 Độ tin cậy: Cao
An issue was discovered in MariaDB Server before 11.4.10, 11.5.x through 11.8.x before 11.8.6, and 12.x before 12.2.2. If the caching_sha2_password authentication plugin is installed, and some user accounts are configured to use it, a large packet can crash the server because sha256_crypt_r uses alloca.
Sản phẩm đối chiếu: MariaDB 10.11.14 Độ tin cậy: Cao
In MariaDB server version through 11.8.5, when server audit plugin is enabled with server_audit_events variable configured with QUERY_DCL, QUERY_DDL, or QUERY_DML filtering, if an authenticated database user invokes a SQL statement prefixed with double-hyphen (—) or hash (#) style comments, the statement is not logged.
Sản phẩm đối chiếu: MariaDB 10.11.14 Độ tin cậy: Cao
MariaDB server is a community developed fork of MySQL server. From versions 10.6.1 to before 10.6.26, 10.11.1 to before 10.11.17, 11.4.1 to before 11.4.11, 11.8.1 to before 11.8.7, and 12.3.1, MariaDB allowed SELECT ... INTO OUTFILE and SELECT ... INTO DUMPFILE without verifying the FILE privilege if the FROM clause contained only subqueries. This issue has been patched in versions 10.6.26, 10.11.17, 11.4.11, 11.8.7, and 12.3.2.