www.lib.caothang.edu.vn
Thư viên Trường Cao Đẳng Kỹ Thuật Cao Thắng
Thư Viện Trường Cao Đẳng Kỹ Thuật Cao Thắng
Lĩnh vực
- Khoa học và Giáo dục / Giáo dục
Nguồn gốc
- Việt Nam
Xếp hạng toàn cầu
- #215.763
Xếp hạng tại Việt Nam
- #3.769
vi
Thư viên Trường Cao Đẳng Kỹ Thuật Cao Thắng
Thư Viện Trường Cao Đẳng Kỹ Thuật Cao Thắng
Điểm càng cao, hệ thống càng ghi nhận được nhiều biện pháp bảo vệ quan sát từ bên ngoài. Trang này không nhằm chứng nhận website uy tín, hợp pháp hay hoàn toàn không có lỗ hổng.
Tính đến 20:06 ngày 10/9/2026, www.lib.caothang.edu.vn đạt 59/100 điểm an toàn (đạt hạng F – “Thấp”). Hệ thống quét tự động của CyStack ghi nhận 16 vấn đề cần xem xét sau khi kiểm tra 94,5% hạng mục. Chủ sở hữu website nên ưu tiên khắc phục “Chứng thư khớp với website”, sau đó rà soát các mục còn lại theo mức độ ảnh hưởng.
CyStack chưa ghi nhận www.lib.caothang.edu.vn hay hạ tầng liên quan trong bất kỳ danh sách cảnh báo lừa đảo, phishing hoặc mã độc nào tại thời điểm quét, sau khi đối chiếu 5 nguồn danh tiếng trực tuyến. Kết quả này phản ánh quan sát từ bên ngoài, không đảm bảo website an toàn tuyệt đối và không xác nhận tư cách pháp lý hay uy tín của tổ chức.
Những địa chỉ, máy chủ và dịch vụ có thể nhìn thấy từ Internet.
Câu hỏi thường gặp
Chứng thư SSL hợp lệ vẫn chưa đủ để khẳng định www.lib.caothang.edu.vn là website an toàn, uy tín hay không có dấu hiệu lừa đảo. Để đánh giá toàn diện hơn, báo cáo còn kiểm tra phishing và mã độc, email lộ lọt, IP và cổng mở, tên miền phụ, công nghệ cùng các CVE có thể liên quan đến phiên bản ghi nhận được.
HTTPS của www.lib.caothang.edu.vn có chứng thư không hợp lệ hoặc không vượt qua bước xác minh. Người vận hành nên kiểm tra ngày hiệu lực, tên miền trên chứng thư và chuỗi tin cậy.
Xem HTTPS và chứng thưNguồn dữ liệu
CyStack tổng hợp kết quả quét từ các hệ thống giám sát an ninh mạng nội bộ, bao gồm CyStack VulnScan và CyStack Threat Intelligence, cùng các nguồn dữ liệu công khai trên Internet. Quá trình đánh giá chỉ quan sát và phân tích thông tin sẵn có, không đăng nhập trái phép, thử mật khẩu, gửi mã khai thác hay làm thay đổi, gián đoạn hệ thống được đánh giá.
Giải pháp CyStack VulnScan liên tục phát hiện tài sản, xác minh lỗ hổng và giúp đội ngũ bảo mật ưu tiên khắc phục trên toàn doanh nghiệp.
Có 3 tiêu chí không đạt hoặc cảnh báo có ảnh hưởng lớn nhất tới kết quả của www.lib.caothang.edu.vn.
Vì sao cần quan tâm
Chứng thư phải liệt kê chính xác tên miền người dùng truy cập trong trường Subject Alternative Names (SAN). Nếu không khớp, trình duyệt sẽ cảnh báo vì chứng thư có thể thuộc về một dịch vụ khác.
Nên làm gì
Cấp và triển khai chứng thư có danh sách SAN bao gồm mọi tên miền công khai được địa chỉ website này phục vụ.
Thông tin chẩn đoán
Bằng chứng chứng thư hiện có chưa đủ để kết luận yêu cầu chứng thư này.
Bằng chứng và phạm vi kiểm tra
Vì sao cần quan tâm
Các dịch vụ cũ như Telnet, FTP và giao thức email hoặc thư mục không mã hóa có thể gửi mật khẩu, dữ liệu ở dạng đọc được. Bên quan sát đường truyền có thể thu thập các thông tin này.
Nên làm gì
Tắt dịch vụ cũ hoặc thay bằng lựa chọn có mã hóa như SSH, SFTP, HTTPS hay phiên bản bảo mật của giao thức email.
Vì sao cần quan tâm
HttpOnly ngăn script trong trình duyệt đọc trực tiếp cookie. Thuộc tính này không khắc phục lỗi chèn script nhưng khiến việc đánh cắp cookie phiên và xác thực khó hơn.
Nên làm gì
Đặt HttpOnly cho cookie phiên và xác thực, trừ khi ứng dụng có nhu cầu rõ ràng và được ghi nhận để đọc chúng bằng mã trong trình duyệt.
Phạm vi của tiêu chí
Mỗi địa chỉ IP công khai được nhóm cùng dịch vụ đang mở, sản phẩm đã nhận diện và các CVE có khả năng liên quan đến phiên bản quan sát được.
Hiện ghi nhận 895 bản ghi email lộ lọt khớp tên miền caothang.edu.vn. Các bản ghi này có thể đã cũ hoặc đã được xử lý. Chủ sở hữu website nên xác minh trước khi đổi mật khẩu hoặc khóa các tài khoản liên quan.
Xem email lộ lọtĐã nhận diện 16 công nghệ trên www.lib.caothang.edu.vn. Trong đó chỉ 2 công nghệ xác định được phiên bản đủ tin cậy để đối chiếu chính xác với CVE.
Xem công nghệ và CVEGhi nhận được 1 IP công khai và 11 cổng đang mở của www.lib.caothang.edu.vn. Cổng mở không tương đương với việc có lỗ hổng, nhưng chủ sở hữu website nên cập nhật thường xuyên và giới hạn truy cập cho từng dịch vụ công khai.
Xem IP và cổng mởGhi nhận 83+ tên miền phụ công khai của caothang.edu.vn. Danh sách này giúp nhận biết thêm các cổng vào như API, hệ thống quản trị hay môi trường thử nghiệm, nhưng không có nghĩa tên miền phụ nào cũng có rủi ro.
Xem tên miền phụBằng chứng và phạm vi kiểm tra
Tiêu chí này chỉ đánh giá phản hồi và nội dung của trang chủ mà hệ thống truy cập được; các trang hoặc luồng đăng nhập khác có thể có cấu hình khác.
Bằng chứng và phạm vi kiểm tra
CVE tiềm năng của sản phẩm này
Exim before 4.95 has a heap-based buffer overflow for the alias list in host_name_lookup in host.c when sender_host_name is set.
NvdChưa nhận diện được sản phẩm
Chưa nhận diện được sản phẩm
Apache is a free and open-source cross-platform web server software.
httpd.apache.orgCVE tiềm năng của sản phẩm này
Exim before 4.95 has a heap-based buffer overflow for the alias list in host_name_lookup in host.c when sender_host_name is set.
NvdCVE tiềm năng của sản phẩm này
Exim before 4.95 has a heap-based buffer overflow for the alias list in host_name_lookup in host.c when sender_host_name is set.
NvdChưa nhận diện được sản phẩm
Exim AUTH Out-Of-Bounds Write Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Exim. Authentication is not required to exploit this vulnerability. The specific flaw exists within the smtp service, which listens on TCP port 25 by default. The issue results from the lack of proper validation of user-supplied data, which can result in a write past the end of a buffer. An attacker can leverage this vulnerability to execute code in the context of the service account. . Was ZDI-CAN-17434.
NvdExim SMTP Challenge Stack-based Buffer Overflow Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Exim. Authentication is not required to exploit this vulnerability. The specific flaw exists within the handling of NTLM challenge requests. The issue results from the lack of proper validation of the length of user-supplied data prior to copying it to a fixed-length stack-based buffer. An attacker can leverage this vulnerability to execute code in the context of the service account. . Was ZDI-CAN-17515.
NvdExim Improper Neutralization of Special Elements Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Exim. Authentication is not required to exploit this vulnerability. The specific flaw exists within the smtp service, which listens on TCP port 25 by default. The issue results from the lack of proper validation of user-supplied data, which can result in a memory corruption condition. An attacker can leverage this vulnerability to execute code in the context of the current process. Was ZDI-CAN-17554.
NvdExim before 4.99.1, with certain non-default rate-limit configurations, allows a remote heap-based buffer overflow because database records are cast directly to internal structures without validation.
NvdIn Exim before 4.99.2, when JSON lookup is enabled, an out-of-bounds heap write can occur when a JSON operator encounters malformed JSON in an untrusted header, because of an incorrect implementation of \ skipping.
NvdIn Exim before 4.99.2, when the SPA authentication driver is used with an adversarial SPA resource, there can be an out-of-bounds write that crashes the connection instance, or erroneous data processing that divulges data from uninitialized heap memory.
NvdExim before 4.99.5 allows directory traversal to access files outside of the spool area, and consequently gain privileges, because arguments related to queue-name are mishandled.
NvdExim before 4.99.5 allows .forward privilege escalation because force_command for a pipe transport is mishandled.
NvdThe STARTTLS feature in Exim through 4.94.2 allows response injection (buffering) during MTA SMTP sending.
NvdA vulnerability was found in Exim and classified as problematic. This issue affects some unknown processing of the component Regex Handler. The manipulation leads to use after free. The name of the patch is 4e9ed49f8f12eb331b29bd5b6dc3693c520fddc2. It is recommended to apply a patch to fix this issue. The identifier VDB-211073 was assigned to this vulnerability.
NvdExim before 4.96 has an invalid free in pam_converse in auths/call_pam.c because store_free is not used after store_malloc.
NvdIn Exim before 4.99.2, on systems using musl libc (not glibc), an attacker can crash the connection instance when malformed DNS data is present in PTR records. This is caused by a dn_expand oddity in octal printing.
NvdExim through 4.97.1 misparses a multiline RFC 2231 header filename, and thus remote attackers can bypass a $mime_filename extension-blocking protection mechanism, and potentially deliver executable attachments to the mailboxes of end users.
NvdExim NTLM Challenge Out-Of-Bounds Read Information Disclosure Vulnerability. This vulnerability allows remote attackers to disclose sensitive information on affected installations of Exim. Authentication is not required to exploit this vulnerability. The specific flaw exists within the handling of NTLM challenge requests. The issue results from the lack of proper validation of user-supplied data, which can result in a read past the end of an allocated data structure. An attacker can leverage this vulnerability to disclose information in the context of the service account. . Was ZDI-CAN-17433.
NvdExim before 4.97.1 allows SMTP smuggling in certain PIPELINING/CHUNKING configurations. Remote attackers can use a published exploitation technique to inject e-mail messages with a spoofed MAIL FROM address, allowing bypass of an SPF protection mechanism. This occurs because Exim supports <LF>.<CR><LF> but some other popular e-mail servers do not.
NvdIn Exim before 4.99.2, when utf8 operators are enabled, there is an out-of-bounds read if large UTF-8 trailing characters are present (malformed UTF-8 header data). Information might be divulged within an error message produced during handling of an unrelated e-mail message.
NvdExim 4.88 before 4.99.4, in some proxy configurations, mishandles certain short payloads, leading to disclosure of uninitialized stack memory values to a client.
NvdExim dnsdb Out-Of-Bounds Read Information Disclosure Vulnerability. This vulnerability allows network-adjacent attackers to disclose sensitive information on affected installations of Exim. Authentication is not required to exploit this vulnerability. The specific flaw exists within the smtp service, which listens on TCP port 25 by default. The issue results from the lack of proper validation of user-supplied data, which can result in a read past the end of an allocated buffer. An attacker can leverage this in conjunction with other vulnerabilities to execute arbitrary code in the context of the service account. . Was ZDI-CAN-17643.
NvdBootstrap is a free and open-source CSS framework directed at responsive, mobile-first front-end web development. It contains CSS and JavaScript-based design templates for typography, forms, buttons, navigation, and other interface components.
getbootstrap.comGoogle Analytics is a free web analytics service that tracks and reports website traffic.
google.com/analyticsjQuery is a JavaScript library which is a free, open-source software designed to simplify HTML DOM tree traversal and manipulation, as well as event handling, CSS animation, and Ajax.
jquery.comOWL Carousel is an enabled jQuery plugin that lets you create responsive carousel sliders.
owlcarousel2.github.io/OwlCarousel2PHP is a general-purpose scripting language used for web development.
php.netExim AUTH Out-Of-Bounds Write Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Exim. Authentication is not required to exploit this vulnerability. The specific flaw exists within the smtp service, which listens on TCP port 25 by default. The issue results from the lack of proper validation of user-supplied data, which can result in a write past the end of a buffer. An attacker can leverage this vulnerability to execute code in the context of the service account. . Was ZDI-CAN-17434.
NvdExim SMTP Challenge Stack-based Buffer Overflow Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Exim. Authentication is not required to exploit this vulnerability. The specific flaw exists within the handling of NTLM challenge requests. The issue results from the lack of proper validation of the length of user-supplied data prior to copying it to a fixed-length stack-based buffer. An attacker can leverage this vulnerability to execute code in the context of the service account. . Was ZDI-CAN-17515.
NvdExim Improper Neutralization of Special Elements Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Exim. Authentication is not required to exploit this vulnerability. The specific flaw exists within the smtp service, which listens on TCP port 25 by default. The issue results from the lack of proper validation of user-supplied data, which can result in a memory corruption condition. An attacker can leverage this vulnerability to execute code in the context of the current process. Was ZDI-CAN-17554.
NvdExim before 4.99.1, with certain non-default rate-limit configurations, allows a remote heap-based buffer overflow because database records are cast directly to internal structures without validation.
NvdIn Exim before 4.99.2, when JSON lookup is enabled, an out-of-bounds heap write can occur when a JSON operator encounters malformed JSON in an untrusted header, because of an incorrect implementation of \ skipping.
NvdIn Exim before 4.99.2, when the SPA authentication driver is used with an adversarial SPA resource, there can be an out-of-bounds write that crashes the connection instance, or erroneous data processing that divulges data from uninitialized heap memory.
NvdExim before 4.99.5 allows directory traversal to access files outside of the spool area, and consequently gain privileges, because arguments related to queue-name are mishandled.
NvdExim before 4.99.5 allows .forward privilege escalation because force_command for a pipe transport is mishandled.
NvdThe STARTTLS feature in Exim through 4.94.2 allows response injection (buffering) during MTA SMTP sending.
NvdA vulnerability was found in Exim and classified as problematic. This issue affects some unknown processing of the component Regex Handler. The manipulation leads to use after free. The name of the patch is 4e9ed49f8f12eb331b29bd5b6dc3693c520fddc2. It is recommended to apply a patch to fix this issue. The identifier VDB-211073 was assigned to this vulnerability.
NvdExim before 4.96 has an invalid free in pam_converse in auths/call_pam.c because store_free is not used after store_malloc.
NvdIn Exim before 4.99.2, on systems using musl libc (not glibc), an attacker can crash the connection instance when malformed DNS data is present in PTR records. This is caused by a dn_expand oddity in octal printing.
NvdExim through 4.97.1 misparses a multiline RFC 2231 header filename, and thus remote attackers can bypass a $mime_filename extension-blocking protection mechanism, and potentially deliver executable attachments to the mailboxes of end users.
NvdExim NTLM Challenge Out-Of-Bounds Read Information Disclosure Vulnerability. This vulnerability allows remote attackers to disclose sensitive information on affected installations of Exim. Authentication is not required to exploit this vulnerability. The specific flaw exists within the handling of NTLM challenge requests. The issue results from the lack of proper validation of user-supplied data, which can result in a read past the end of an allocated data structure. An attacker can leverage this vulnerability to disclose information in the context of the service account. . Was ZDI-CAN-17433.
NvdExim before 4.97.1 allows SMTP smuggling in certain PIPELINING/CHUNKING configurations. Remote attackers can use a published exploitation technique to inject e-mail messages with a spoofed MAIL FROM address, allowing bypass of an SPF protection mechanism. This occurs because Exim supports <LF>.<CR><LF> but some other popular e-mail servers do not.
NvdIn Exim before 4.99.2, when utf8 operators are enabled, there is an out-of-bounds read if large UTF-8 trailing characters are present (malformed UTF-8 header data). Information might be divulged within an error message produced during handling of an unrelated e-mail message.
NvdExim 4.88 before 4.99.4, in some proxy configurations, mishandles certain short payloads, leading to disclosure of uninitialized stack memory values to a client.
NvdExim dnsdb Out-Of-Bounds Read Information Disclosure Vulnerability. This vulnerability allows network-adjacent attackers to disclose sensitive information on affected installations of Exim. Authentication is not required to exploit this vulnerability. The specific flaw exists within the smtp service, which listens on TCP port 25 by default. The issue results from the lack of proper validation of user-supplied data, which can result in a read past the end of an allocated buffer. An attacker can leverage this in conjunction with other vulnerabilities to execute arbitrary code in the context of the service account. . Was ZDI-CAN-17643.
NvdExim AUTH Out-Of-Bounds Write Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Exim. Authentication is not required to exploit this vulnerability. The specific flaw exists within the smtp service, which listens on TCP port 25 by default. The issue results from the lack of proper validation of user-supplied data, which can result in a write past the end of a buffer. An attacker can leverage this vulnerability to execute code in the context of the service account. . Was ZDI-CAN-17434.
NvdExim SMTP Challenge Stack-based Buffer Overflow Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Exim. Authentication is not required to exploit this vulnerability. The specific flaw exists within the handling of NTLM challenge requests. The issue results from the lack of proper validation of the length of user-supplied data prior to copying it to a fixed-length stack-based buffer. An attacker can leverage this vulnerability to execute code in the context of the service account. . Was ZDI-CAN-17515.
NvdExim Improper Neutralization of Special Elements Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Exim. Authentication is not required to exploit this vulnerability. The specific flaw exists within the smtp service, which listens on TCP port 25 by default. The issue results from the lack of proper validation of user-supplied data, which can result in a memory corruption condition. An attacker can leverage this vulnerability to execute code in the context of the current process. Was ZDI-CAN-17554.
NvdExim before 4.99.1, with certain non-default rate-limit configurations, allows a remote heap-based buffer overflow because database records are cast directly to internal structures without validation.
NvdIn Exim before 4.99.2, when JSON lookup is enabled, an out-of-bounds heap write can occur when a JSON operator encounters malformed JSON in an untrusted header, because of an incorrect implementation of \ skipping.
NvdIn Exim before 4.99.2, when the SPA authentication driver is used with an adversarial SPA resource, there can be an out-of-bounds write that crashes the connection instance, or erroneous data processing that divulges data from uninitialized heap memory.
NvdExim before 4.99.5 allows directory traversal to access files outside of the spool area, and consequently gain privileges, because arguments related to queue-name are mishandled.
NvdExim before 4.99.5 allows .forward privilege escalation because force_command for a pipe transport is mishandled.
NvdThe STARTTLS feature in Exim through 4.94.2 allows response injection (buffering) during MTA SMTP sending.
NvdA vulnerability was found in Exim and classified as problematic. This issue affects some unknown processing of the component Regex Handler. The manipulation leads to use after free. The name of the patch is 4e9ed49f8f12eb331b29bd5b6dc3693c520fddc2. It is recommended to apply a patch to fix this issue. The identifier VDB-211073 was assigned to this vulnerability.
NvdExim before 4.96 has an invalid free in pam_converse in auths/call_pam.c because store_free is not used after store_malloc.
NvdIn Exim before 4.99.2, on systems using musl libc (not glibc), an attacker can crash the connection instance when malformed DNS data is present in PTR records. This is caused by a dn_expand oddity in octal printing.
NvdExim through 4.97.1 misparses a multiline RFC 2231 header filename, and thus remote attackers can bypass a $mime_filename extension-blocking protection mechanism, and potentially deliver executable attachments to the mailboxes of end users.
NvdExim NTLM Challenge Out-Of-Bounds Read Information Disclosure Vulnerability. This vulnerability allows remote attackers to disclose sensitive information on affected installations of Exim. Authentication is not required to exploit this vulnerability. The specific flaw exists within the handling of NTLM challenge requests. The issue results from the lack of proper validation of user-supplied data, which can result in a read past the end of an allocated data structure. An attacker can leverage this vulnerability to disclose information in the context of the service account. . Was ZDI-CAN-17433.
NvdExim before 4.97.1 allows SMTP smuggling in certain PIPELINING/CHUNKING configurations. Remote attackers can use a published exploitation technique to inject e-mail messages with a spoofed MAIL FROM address, allowing bypass of an SPF protection mechanism. This occurs because Exim supports <LF>.<CR><LF> but some other popular e-mail servers do not.
NvdIn Exim before 4.99.2, when utf8 operators are enabled, there is an out-of-bounds read if large UTF-8 trailing characters are present (malformed UTF-8 header data). Information might be divulged within an error message produced during handling of an unrelated e-mail message.
NvdExim 4.88 before 4.99.4, in some proxy configurations, mishandles certain short payloads, leading to disclosure of uninitialized stack memory values to a client.
NvdExim dnsdb Out-Of-Bounds Read Information Disclosure Vulnerability. This vulnerability allows network-adjacent attackers to disclose sensitive information on affected installations of Exim. Authentication is not required to exploit this vulnerability. The specific flaw exists within the smtp service, which listens on TCP port 25 by default. The issue results from the lack of proper validation of user-supplied data, which can result in a read past the end of an allocated buffer. An attacker can leverage this in conjunction with other vulnerabilities to execute arbitrary code in the context of the service account. . Was ZDI-CAN-17643.
NvdCác đánh giá hoàn tất gần đây, ưu tiên website cùng lĩnh vực, quốc gia hoặc mức an toàn để bạn dễ so sánh.