![]() |
Home ▼ Bookkeeping
Online ▼ Security
Audits ▼
Managed
DNS ▼
About
Order
FAQ
Acceptable Use Policy
Dynamic DNS Clients
Configure Domains Dyanmic DNS Update Password Network
Monitor ▼
Enterprise Package
Advanced Package
Standard Package
Free Trial
FAQ
Price/Feature Summary
Order/Renew
Examples
Configure/Status Alert Profiles | ||
Search results found more than 50 Tests and more than 50 CVE entries matching "backdoor"
JUNG Smart Visu Server Multiple Vulnerabilities
Summary: JUNG Smart Visu Server is prone to multiple vulnerabilities. Vulnerability Insight: JUNG Smart Visu Server is prone to multiple vulnerabilities: - Path ...
Test ID: 1.3.6.1.4.1.25623.1.0.106577
NUUO NVR < 3.9.1 Backdoor Activated - Active Check
Summary: The Backdoor in NUUO NVR is active. Vulnerability Insight: If the file '/tmp/moses' is present on the device unauthenticated remote attacker can list all of t...
Test ID: 1.3.6.1.4.1.25623.1.0.141487 CVE: CVE-2018-1150
WordPress TC Custom JavaScript Plugin < 1.2.2 XSS Vulnerability
Summary: The WordPress plugin 'TC Custom JavaScript' is prone to a cross-site scripting (XSS) vulnerability. Vulnerability Insight: An attacker could send a POST reque...
Test ID: 1.3.6.1.4.1.25623.1.0.112797 CVE: CVE-2020-14063
Multiple IP-Cameras (P2P) WIFICAM Cameras Multiple Vulnerabilities
Summary: Multiple IP-Camera devices are prone to multiple vulnerabilities. This vulnerability was known to be exploited by the IoT Botnet 'Reaper' in 2017. Vul...
Test ID: 1.3.6.1.4.1.25623.1.0.106636
Apache HTTP Server 'mod_rootme' Backdoor
Summary: The remote system appears to be running the mod_rootme module, this module silently allows a user to gain a root shell access to the machine via HTTP requests. Sol...
Test ID: 1.3.6.1.4.1.25623.1.0.13644
TFTP backdoor
Summary: A TFTP server is running on this port. However, while trying to fetch some file, we retrieved an executable file. This is probably a backdoor. Solutio...
Test ID: 1.3.6.1.4.1.25623.1.0.18263
FsSniffer Detection
Summary: This host appears to be running FsSniffer on this port. FsSniffer is backdoor which allows an intruder to steal PoP3/FTP and other passwords you use on your syst...
Test ID: 1.3.6.1.4.1.25623.1.0.11854
Multiple Barracuda Products Security Bypass and Backdoor Unauthorized Access Vulnerabilities (SSH)
Summary: Multiple Barracuda products are prone to a security-bypass vulnerability and multiple unauthorized-access vulnerabilities. Vulnerability Impact: Attackers can...
Test ID: 1.3.6.1.4.1.25623.1.0.103646
HACKER defender finder
Summary: This script checks whether the remote host is running the Hacker Defender backdoor. Vulnerability Insight: Hacker Defender is a rootkit for Windows. Among oth...
Test ID: 1.3.6.1.4.1.25623.1.0.15517
NEC Enterprise Server Backdoor Account (Telnet)
Summary: NEC Enterprise Server is using a backdoor account in all versions of the application. Vulnerability Impact: Attackers can exploit this issue to gain unauthori...
Test ID: 1.3.6.1.4.1.25623.1.0.103498
Portal of Doom
Description: Portal of Doom is installed. This backdoor allows anyone to partially take the control of the remote system. An attacker may use it to steal yo...
Test ID: 1.3.6.1.4.1.25623.1.0.10186 CVE: CVE-1999-0660
Bagle remover
Description: The remote host had the bagle virus installed. Nessus probably removed it by connecting to port 6777 of this host and use the built-in removal command of this ...
Test ID: 1.3.6.1.4.1.25623.1.0.12027
Sony IPELA Engine IP Cameras Backdoor Vulnerability
Summary: on a Sony IPELA Engine IP Camera is prone to a backdoor vulnerability. Vulnerability Insight: The flaw is due to an improper validation of web requests passed...
Test ID: 1.3.6.1.4.1.25623.1.0.107106
eSeSIX Thintune Thin Client Multiple Vulnerabilities
Summary: Multiple security vulnerabilities have been found in Thintune, one of them is a backdoor password ('jstwo') allowing complete access to the system. Solution: ...
Test ID: 1.3.6.1.4.1.25623.1.0.13839
Foxit Reader Arbitrary Code Execution Vulnerability - Linux
Summary: Foxit Reader is prone to an arbitrary code execution vulnerability. Vulnerability Insight: The flaw exists due to Foxit Reader's core files are world-writable...
Test ID: 1.3.6.1.4.1.25623.1.0.809333 CVE: CVE-2016-8856
Microsoft Frontpage dvwssr.dll backdoor
Description: The dll '/_vti_bin/_vti_aut/dvwssr.dll' seems to be present. This dll contains a bug which allows anyone with authoring web permissions on this system to a...
Test ID: 1.3.6.1.4.1.25623.1.0.10369 CVE: CVE-2000-0260 Bugtraq ID: 1109
HP D2D/StorOnce Storage Unit Backdoor (SSH)
Summary: HP D2D/StorOnce Storage Units are prone to a security-bypass vulnerability. Vulnerability Insight: The HP D2D/StorOnce Storage Units contains a backdoor. SSH&...
Test ID: 1.3.6.1.4.1.25623.1.0.103746 CVE: CVE-2013-2342
Check MK < 1.6.0p25, 2.0.x < 2.0.0p4 XSS Vulnerability
Summary: Check MK is prone to a cross-site scripting (XSS) vulnerability in the management web console. Vulnerability Insight: The CheckMK management web console does ...
Test ID: 1.3.6.1.4.1.25623.1.0.146390 CVE: CVE-2021-36563
Unpassworded 'bash' account
Summary: The account 'bash' has no password set. Vulnerability Insight: This account was probably created by a backdoor installed by a fake Linux Redhat patch. &n...
Test ID: 1.3.6.1.4.1.25623.1.0.15583 CVE: CVE-1999-0502
Netgear/Linksys Routers Backdoor
Summary: The remote Linksys/Netgear Router has a backdoor on port 32764. Vulnerability Insight: By sending a special crafted request to port 32764 of the router, it is...
Test ID: 1.3.6.1.4.1.25623.1.0.103866
4553 Parasite Mothership Detect
Summary: The backdoor '4553' seems to be installed on this host, which indicates it has been compromised. Solution: Re-install this host. CVSS Score: 9...
Test ID: 1.3.6.1.4.1.25623.1.0.11187
SyGate Backdoor
Description: SyGate engine remote controller seems to be running on this port. It may be used by malicious users which are on the same subnet as this host to reconfigure the...
Test ID: 1.3.6.1.4.1.25623.1.0.10274 CVE: CVE-2000-0113 Bugtraq ID: 952
XOOPS 'findusers.php' SQL Injection Vulnerability
Summary: XOOPS is prone to an SQL injection vulnerability. Vulnerability Insight: The flaw exists due to XOOPS allowing remote authenticated administrators to execute ...
Test ID: 1.3.6.1.4.1.25623.1.0.108137 CVE: CVE-2017-7290
D-Link DNS/DNR Devices Multiple Vulnerabilities (SAP10383) - Active Check
Summary: Multiple D-Link DNS and DNR devices are prone to multiple vulnerabilities. Vulnerability Insight: The following vulnerabilities exist: - CVE-2024...
Test ID: 1.3.6.1.4.1.25623.1.0.152068
FTP server accepts a bad sequence of commands
Summary: The remote FTP service accepts commands in any order. Vulnerability Insight: The remote server advertises itself as being a FTP server, but it accepts command...
Test ID: 1.3.6.1.4.1.25623.1.0.80063
ZTE ZXR10 Router < 3.00.40 Multiple Vulnerabilities
Summary: ZTE ZXR10 Router devices have a backdoor account with hardcoded credentials. Vulnerability Impact: This issue may be exploited by a remote attacker to gain full ...
Test ID: 1.3.6.1.4.1.25623.1.0.107254 CVE: CVE-2017-10931
OpenX 'flowplayer-3.1.1.min.js' Backdoor Vulnerability
Summary: OpenX is prone to a backdoor vulnerability. Vulnerability Insight: The security issue is caused due to the distribution of a compromised OpenX Source source cod...
Test ID: 1.3.6.1.4.1.25623.1.0.103755 CVE: CVE-2013-4211
Sitecom WLM-3500 Backdoor Accounts (HTTP)
Summary: Sitecom WLM-3500 routers contain an undocumented access backdoor. Vulnerability Insight: These hard-coded accounts are persistently stored inside the d...
Test ID: 1.3.6.1.4.1.25623.1.0.803193
FTP server does not accept any command
Summary: The remote FTP service is not working properly. Vulnerability Insight: The remote server advertises itself as being a FTP server, but it does not accept any c...
Test ID: 1.3.6.1.4.1.25623.1.0.80064
Possible Backdoor
Summary: Look for potential backdoors. Solution: Clean up the target host from the potential backdoor. CVSS Score: 10.0 CVSS Vector: AV:N/AC:L...
Test ID: 1.3.6.1.4.1.25623.1.0.105238
Port TCP:0 Open
Summary: TCP port 0 is open on the remote host. This is highly suspicious as this TCP port is reserved and should not be used. This might be a backdoor (REx). Solution:&nbs...
Test ID: 1.3.6.1.4.1.25623.1.0.18164
Alcatel OmniSwitch 7700/7800 switches backdoor
Summary: The remote host seems to be a backdoored Alcatel OmniSwitch 7700/7800. Vulnerability Impact: An attacker can gain full access to any device running AOS...
Test ID: 1.3.6.1.4.1.25623.1.0.11170 CVE: CVE-2002-1272
MoonLit Virus Backdoor
Summary: The system is infected by the MoonLit virus, the backdoor port is open. Backdoor.Moonlit is a Trojan horse program that can download and execute files, and may a...
Test ID: 1.3.6.1.4.1.25623.1.0.15586
Horde Groupware Webmail <= 5.2.22 RCE Vulnerability - Windows
Summary: Horde Groupware Webmail is prone to an authenticated remote code execution (RCE) vulnerability. Vulnerability Insight: Horde/Form/Type.php contains a vulnerab...
Test ID: 1.3.6.1.4.1.25623.1.0.142488 CVE: CVE-2019-9858
WordPress MapPress Plugin < 2.53.9 Multiple Vulnerabilities
Summary: The WordPress plugin 'MapPress' is prone to multiple vulnerabilities. Vulnerability Insight: One vulnerability that allowed stored cross-site scripting ...
Test ID: 1.3.6.1.4.1.25623.1.0.112735 CVE: CVE-2020-12077
Netcore/Netis Devices Backdoor Access (UDP)
Summary: Netcore/Netis devices are exposing a backdoor access. Vulnerability Insight: Affected devices include a backdoor service listening on UDP port 53413. Vuln...
Test ID: 1.3.6.1.4.1.25623.1.0.105075
LimeSurvey 2.05x < 2.06+ Multiple Vulnerabilities
Summary: LimeSurvey is prone to multiple vulnerabilities Vulnerability Insight: The following vulnerabilities exist: - Unauthenticated local file disclosure ...
Test ID: 1.3.6.1.4.1.25623.1.0.106064
PHP File Manager Backdoor Vulnerability
Summary: PHP File Manager consists of a default backdoor user. Vulnerability Insight: A default hidden user with admin permissions exists in the db/valid.users file. Thi...
Test ID: 1.3.6.1.4.1.25623.1.0.106034
D-Link DIR-850L Rev.A1 < 1.20 / Rev.B1 < 2.20 XSS / Backdoor / Code Execution Vulnerabilities
Summary: D-Link DIR-850L devices suffer from cross-site scripting (XSS), access bypass, backdoor, bruteforcing, information disclosure, remote code execution (RCE), and denial ...
Test ID: 1.3.6.1.4.1.25623.1.0.107242
Linux FTP backdoor
Description: There is a backdoor in the old ftp daemons of Linux, which allows remote users to log in as 'NULL', with password 'NULL', and to get root privileges over FTP. ...
Test ID: 1.3.6.1.4.1.25623.1.0.10080 CVE: CVE-1999-0452
CDK Detect
Description: The remote host appears to be running CDK, which is a backdoor that can be used to control your system. To use it, an attacker just has to connect &n...
Test ID: 1.3.6.1.4.1.25623.1.0.10036 CVE: CVE-1999-0660
CCleaner Cloud 'CCleaner.exe' Backdoor Trojan Vulnerability - Windows
Summary: CCleaner Cloud agent is prone to backdoor trojan installation vulnerability. Vulnerability Insight: The flaw exists due to an unauthorized modification of the...
Test ID: 1.3.6.1.4.1.25623.1.0.811780
WordPress Captcha Plugin < 4.4.5 Backdoor Vulnerability
Summary: The WordPress plugin 'Captcha' is prone to a backdoor vulnerability. Affected Software/OS: WordPress Captcha plugin between version 4.3.6 and 4.4.4. &nbs...
Test ID: 1.3.6.1.4.1.25623.1.0.112155
Bugbear.B web backdoor
Summary: Your system seems to be infected by the Bugbear.B virus (its backdoor has been detected on port 81). Solution: Use your favorite antivirus to disinfect your&n...
Test ID: 1.3.6.1.4.1.25623.1.0.11707
D-Link Multiple Devices Backdoor
Summary: Various D-Link DSL routers are susceptible to a remote authentication bypass vulnerability. Vulnerability Insight: By setting the User-Agent header to 'xmlset_r...
Test ID: 1.3.6.1.4.1.25623.1.0.103810 CVE: CVE-2013-6026
D-Link DIR-850L Backdoor Account / Hardcoded Credentials (Telnet)
Summary: The D-Link DIR-850L router has a backdoor account with hardcoded credentials. Vulnerability Insight: It was possible to login with the telnet credentials 'Alphanetwo...
Test ID: 1.3.6.1.4.1.25623.1.0.107301 CVE: CVE-2017-14421
Fake FTP server accepts any command
Summary: The remote FTP service is not working properly Vulnerability Insight: The remote server advertises itself as being a FTP server, but it accepts any command, w...
Test ID: 1.3.6.1.4.1.25623.1.0.80062
NetSphere Backdoor
Description: NetSphere is installed. This backdoor allows anyone to partially take control of the remote system. An attacker may use this vulnerability to ...
Test ID: 1.3.6.1.4.1.25623.1.0.10005 CVE: CVE-1999-0660
Wollf backdoor detection
Summary: This host appears to be running Wollf on this port. Wollf Can be used as a Backdoor which allows an intruder gain remote access to files on your computer. If you...
Test ID: 1.3.6.1.4.1.25623.1.0.11881
CCleaner 'CCleaner.exe' Backdoor Trojan Vulnerability - Windows
Summary: CCleaner is prone to backdoor trojan installation vulnerability. Vulnerability Insight: The flaw exists due to an unauthorized modification of the 'CCleaner.e...
Test ID: 1.3.6.1.4.1.25623.1.0.811779
CVE-2020-28593
A unauthenticated backdoor exists in the configuration server
functionality of Cosori Smart 5.8-Quart Air Fryer CS158-AF 1.1.0. A
specially crafted JSON object can lead to code execution. An atta...
CVE-2019-10842
Arbitrary code execution (via backdoor code) was discovered in
bootstrap-sass 3.2.0.3, when downloaded from rubygems.org. An
unauthenticated attacker can craft the ___cfduid cookie value with
bas...
CVE-2019-15224
The rest-client gem 1.6.10 through 1.6.13 for Ruby, as distributed on
RubyGems.org, included a code-execution backdoor inserted by a third
party. Versions <=1.6.9 and >=1.6.14 are unaffected.
CVE-2022-34059
The Sixfab-Tool in PyPI v0.0.2 to v0.0.3 was discovered to contain a
code execution backdoor via the request package. This vulnerability
allows attackers to access sensitive user information and ...
CVE-2019-12776
An issue was discovered on the ENTTEC Datagate MK2, Storm 24,
Pixelator, and E-Streamer MK2 with firmware 70044_update_05032019-482.
They include a hard-coded SSH backdoor for remote SSH and SCP ...
CVE-2022-42038
The d8s-ip-addresses package for Python, as distributed on PyPI,
included a potential code-execution backdoor inserted by a third
party. The backdoor is the democritus-csv package. The affected
v...
CVE-2022-44054
The d8s-xml for python, as distributed on PyPI, included a potential
code-execution backdoor inserted by a third party. A potential code
execution backdoor inserted by third parties is the democr...
CVE-2021-40906
CheckMK Raw Edition software (versions 1.5.0 to 1.6.0) does not
sanitise the input of a web service parameter that is in an
unauthenticated zone. This Reflected XSS allows an attacker to open a
b...
CVE-2022-40427
The d8s-domains for python, as distributed on PyPI, included a
potential code-execution backdoor inserted by a third party. The
backdoor is the democritus-networking package. The affected version...
CVE-2019-6548
GE Communicator, all versions prior to 4.0.517, contains two backdoor
accounts with hardcoded credentials, which may allow control over the
database. This service is inaccessible to attackers if ...
CVE-2018-6361
Easy Hosting Control Panel (EHCP) v0.37.12.b has XSS via the op
parameter, as demonstrated by adding a backdoor FTP account.
CVE-2017-11436
D-Link DIR-615 before v20.12PTb04 has a second admin account with a
0x1 BACKDOOR value, which might allow remote attackers to obtain
access via a TELNET connection.
CVE-2022-34055
The drxhello package in PyPI v0.0.1 was discovered to contain a code
execution backdoor via the request package. This vulnerability allows
attackers to access sensitive user information and digit...
CVE-2022-47209
A support user exists on the device and appears to be a backdoor for
Technical Support staff. The default password for this account is
“ support” and cannot be changed by a u...
CVE-2013-6360
TRENDnet TS-S402 has a backdoor to enable TELNET.
CVE-2017-7462
Intellinet NFC-30ir IP Camera has a vendor backdoor that can allow a
remote attacker access to a vendor-supplied CGI script in the web
directory.
CVE-2022-38880
The d8s-urls for python, as distributed on PyPI, included a potential
code-execution backdoor inserted by a third party. The affected
version is 0.1.0.
CVE-2022-4093
SQL injection attacks can result in unauthorized access to sensitive
data, such as passwords, credit card details, or personal user
information. Many high-profile data breaches in recent years ha...
CVE-2022-32997
The RootInteractive package in PyPI v0.0.5 to v0.0.19b0 was discovered
to contain a code execution backdoor via the request package. This
vulnerability allows attackers to access sensitive user i...
CVE-2023-49963
DYMO LabelWriter Print Server through 2.366 contains a backdoor hard-
coded password that could allow an attacker to take control.
CVE-2023-24107
hour_of_code_python_2015 commit
520929797b9ca43bb818b2e8f963fb2025459fa3 was discovered to contain a
code execution backdoor via the request package (requirements.txt).
This vulnerability allows ...
CVE-2014-3205
backupmgt/pre_connect_check.php in Seagate BlackArmor NAS contains a
hard-coded password of '!~@##$$%FREDESWWSED' for a backdoor user.
CVE-2022-42039
The d8s-lists package for Python, as distributed on PyPI, included a
potential code-execution backdoor inserted by a third party. The
backdoor is the democritus-dicts package. The affected versio...
CVE-2019-7276
Optergy Proton/Enterprise devices allow Remote Root Code Execution via
a Backdoor Console.
CVE-2017-10845
Wi-Fi STATION L-02F Software version V10g and earlier allows remote
attackers to access the device with administrative privileges and
perform unintended operations through a backdoor account.
CVE-2022-42040
The d8s-algorithms package for Python, as distributed on PyPI,
included a potential code-execution backdoor inserted by a third
party. The backdoor is the democritus-dicts package. The affected
v...
CVE-2019-19033
Jalios JCMS 10 allows attackers to access any part of the website and
the WebDAV server with administrative privileges via a backdoor
account, by using any username and the hardcoded dev password...
CVE-2022-44050
The d8s-networking for python, as distributed on PyPI, included a
potential code-execution backdoor inserted by a third party. A
potential code execution backdoor inserted by third parties is the...
CVE-2019-17268
The omniauth-weibo-oauth2 gem 0.4.6 for Ruby, as distributed on
RubyGems.org, included a code-execution backdoor inserted by a third
party. Versions through 0.4.5, and 0.5.1 and later, are unaffe...
CVE-2021-33216
An issue was discovered in CommScope Ruckus IoT Controller 1.7.1.0 and
earlier. An Undocumented Backdoor exists, allowing shell access via a
developer account.
CVE-2022-40429
The d8s-ip-addresses for python, as distributed on PyPI, included a
potential code-execution backdoor inserted by a third party. The
backdoor is the democritus-networking package. The affected ve...
CVE-2022-40431
The d8s-pdfs for python, as distributed on PyPI, included a potential
code-execution backdoor inserted by a third party. The backdoor is the
democritus-networking package. The affected version is...
CVE-2022-33000
The ML-Scanner package in PyPI v0.1.0 to v0.1.5 was discovered to
contain a code execution backdoor via the request package. This
vulnerability allows attackers to access sensitive user informati...
CVE-2009-5025
A backdoor (aka BMSA-2009-07) was found in PyForum v1.0.3 where an
attacker who knows a valid user email could force a password reset on
behalf of that user.
CVE-2015-2882
Philips In.Sight B120/37 has a password of b120root for the backdoor
root account, a password of /ADMIN/ for the backdoor admin account, a
password of merlin for the backdoor mg3500 account, a pa...
CVE-2021-40903
A vulnerability in Antminer Monitor 0.50.0 exists because of backdoor
or misconfiguration inside a settings file in flask server. Settings
file has a predefined secret string, which would be rand...
CVE-2022-40432
The d8s-strings for python, as distributed on PyPI, included a
potential code-execution backdoor inserted by a third party. The
backdoor is the democritus-hypothesis package. The affected version...
CVE-2017-7290
SQL injection vulnerability in XOOPS 2.5.7.2 and other versions before
2.5.8.1 allows remote authenticated administrators to execute
arbitrary SQL commands via the url parameter to findusers.php....
CVE-2022-46609
Python3-RESTfulAPI commit d9907f14e9e25dcdb54f5b22252b0e9452e3970e and
e772e0beee284c50946e94c54a1d43071ca78b74 was discovered to contain a
code execution backdoor via the request package. This v...
CVE-2021-36563
The CheckMK management web console (versions 1.5.0 to 2.0.0) does not
sanitise user input in various parameters of the WATO module. This
allows an attacker to open a backdoor on the device with H...
CVE-2017-8218
vsftpd on TP-Link C2 and C20i devices through firmware 0.9.1 4.2
v0032.0 Build 160706 Rel.37961n has a backdoor admin account with the
1234 password, a backdoor guest account with the guest passw...
CVE-2010-0103
UsbCharger.dll in the Energizer DUO USB battery charger software
contains a backdoor that is implemented through the Arucer.dll file in
the %WINDIR%\system32 directory, which allows remote attack...
CVE-2023-26243
An issue was discovered in the Hyundai Gen5W_L in-vehicle infotainment
system AE_E_PE_EUR.S5W_L001.001.211214. The decryption binary used to
decrypt firmware files has an information leak that al...
CVE-2004-0260
The AddToMailingList function in CactuSoft CactuShop 5.0 Lite contains
a backdoor that allows remote attackers to delete arbitrary files via
an email address that starts with |||.
CVE-2022-42042
The d8s-networking package for Python, as distributed on PyPI,
included a potential code-execution backdoor inserted by a third
party. The backdoor is the democritus-hashes package. The affected
...
CVE-2022-40811
The d8s-urls for python, as distributed on PyPI, included a potential
code-execution backdoor inserted by a third party. The backdoor is the
democritus-file-system package. The affected version i...
CVE-2022-41380
The d8s-yaml package for Python, as distributed on PyPI, included a
potential code-execution backdoor inserted by a third party. The
backdoor is the democritus-file-system package. The affected v...
CVE-2022-41384
The d8s-domains package for Python, as distributed on PyPI, included a
potential code-execution backdoor inserted by a third party. The
backdoor is the democritus-urls package. The affected versi...
CVE-2022-34056
The Watertools package in PyPI v0.0.0 was discovered to contain a code
execution backdoor via the request package. This vulnerability allows
attackers to access sensitive user information and dig...
CVE-2022-44051
The d8s-stats for python, as distributed on PyPI, included a potential
code-execution backdoor inserted by a third party. A potential code
execution backdoor inserted by third parties is the demo...