Vulnerability   
Search   
    Search 324607 CVE descriptions
and 146377 test descriptions,
access 10,000+ cross references.
Tests   CVE   All  

Search results found more than 50 Tests and more than 50 CVE entries matching "backdoor"

JUNG Smart Visu Server Multiple Vulnerabilities
Summary: JUNG Smart Visu Server is prone to multiple vulnerabilities.  Vulnerability Insight: JUNG Smart Visu Server is prone to multiple vulnerabilities:   - Path ...
Test ID: 1.3.6.1.4.1.25623.1.0.106577  

NUUO NVR < 3.9.1 Backdoor Activated - Active Check
Summary: The Backdoor in NUUO NVR is active.  Vulnerability Insight: If the file '/tmp/moses' is present on the device  unauthenticated remote attacker can list all of t...
Test ID: 1.3.6.1.4.1.25623.1.0.141487  CVE: CVE-2018-1150  

WordPress TC Custom JavaScript Plugin < 1.2.2 XSS Vulnerability
Summary: The WordPress plugin 'TC Custom JavaScript' is prone to a  cross-site scripting (XSS) vulnerability.  Vulnerability Insight: An attacker could send a POST reque...
Test ID: 1.3.6.1.4.1.25623.1.0.112797  CVE: CVE-2020-14063  

Multiple IP-Cameras (P2P) WIFICAM Cameras Multiple Vulnerabilities
Summary: Multiple IP-Camera devices are prone to multiple  vulnerabilities.   This vulnerability was known to be exploited by the IoT Botnet 'Reaper' in 2017.  Vul...
Test ID: 1.3.6.1.4.1.25623.1.0.106636  

Apache HTTP Server 'mod_rootme' Backdoor
Summary: The remote system appears to be running the mod_rootme module,  this module silently allows a user to gain a root shell access to the machine via HTTP requests.  Sol...
Test ID: 1.3.6.1.4.1.25623.1.0.13644  

TFTP backdoor
Summary: A TFTP server is running on this port.  However, while trying to fetch some file, we retrieved an executable file.   This is probably a backdoor.  Solutio...
Test ID: 1.3.6.1.4.1.25623.1.0.18263  

FsSniffer Detection
Summary: This host appears to be running FsSniffer on this port.   FsSniffer is backdoor which allows an intruder to steal  PoP3/FTP and other passwords you use on your syst...
Test ID: 1.3.6.1.4.1.25623.1.0.11854  

Multiple Barracuda Products Security Bypass and Backdoor Unauthorized Access Vulnerabilities (SSH)
Summary: Multiple Barracuda products are prone to a security-bypass  vulnerability and multiple unauthorized-access vulnerabilities.  Vulnerability Impact: Attackers can...
Test ID: 1.3.6.1.4.1.25623.1.0.103646  

HACKER defender finder
Summary: This script checks whether the remote host is running the Hacker  Defender backdoor.  Vulnerability Insight: Hacker Defender is a rootkit for Windows. Among oth...
Test ID: 1.3.6.1.4.1.25623.1.0.15517  

NEC Enterprise Server Backdoor Account (Telnet)
Summary: NEC Enterprise Server is using a backdoor account in all  versions of the application.  Vulnerability Impact: Attackers can exploit this issue to gain unauthori...
Test ID: 1.3.6.1.4.1.25623.1.0.103498  

Portal of Doom
Description: Portal of Doom is installed.   This backdoor allows anyone to partially take the control of  the remote system.  An attacker may use it to steal yo...
Test ID: 1.3.6.1.4.1.25623.1.0.10186  CVE: CVE-1999-0660  

Bagle remover
Description:  The remote host had the bagle virus installed. Nessus probably  removed it by connecting to port 6777 of this host and use the  built-in removal command of this ...
Test ID: 1.3.6.1.4.1.25623.1.0.12027  

Sony IPELA Engine IP Cameras Backdoor Vulnerability
Summary: on a Sony IPELA Engine IP Camera is prone to a backdoor vulnerability.  Vulnerability Insight: The flaw is due to an improper validation of  web requests passed...
Test ID: 1.3.6.1.4.1.25623.1.0.107106  

eSeSIX Thintune Thin Client Multiple Vulnerabilities
Summary: Multiple security vulnerabilities have been found in Thintune,  one of them is a backdoor password ('jstwo') allowing complete access to the system.  Solution: ...
Test ID: 1.3.6.1.4.1.25623.1.0.13839  

Foxit Reader Arbitrary Code Execution Vulnerability - Linux
Summary: Foxit Reader is prone to an arbitrary code execution vulnerability.  Vulnerability Insight: The flaw exists due to Foxit Reader's core  files are world-writable...
Test ID: 1.3.6.1.4.1.25623.1.0.809333  CVE: CVE-2016-8856  

Microsoft Frontpage dvwssr.dll backdoor
Description:  The dll '/_vti_bin/_vti_aut/dvwssr.dll' seems to be present.  This dll contains a bug which allows anyone with authoring web permissions on this system to a...
Test ID: 1.3.6.1.4.1.25623.1.0.10369  CVE: CVE-2000-0260  Bugtraq ID: 1109  

HP D2D/StorOnce Storage Unit Backdoor (SSH)
Summary: HP D2D/StorOnce Storage Units are prone to a security-bypass  vulnerability.  Vulnerability Insight: The HP D2D/StorOnce Storage Units contains a backdoor. SSH&...
Test ID: 1.3.6.1.4.1.25623.1.0.103746  CVE: CVE-2013-2342  

Check MK < 1.6.0p25, 2.0.x < 2.0.0p4 XSS Vulnerability
Summary: Check MK is prone to a cross-site scripting (XSS) vulnerability  in the management web console.  Vulnerability Insight: The CheckMK management web console does ...
Test ID: 1.3.6.1.4.1.25623.1.0.146390  CVE: CVE-2021-36563  

Unpassworded 'bash' account
Summary: The account 'bash' has no password set.  Vulnerability Insight: This account was probably created by a backdoor installed  by a fake Linux Redhat patch. &n...
Test ID: 1.3.6.1.4.1.25623.1.0.15583  CVE: CVE-1999-0502  

Netgear/Linksys Routers Backdoor
Summary: The remote Linksys/Netgear Router has a backdoor on port 32764.  Vulnerability Insight: By sending a special crafted request to port 32764 of the router, it  is...
Test ID: 1.3.6.1.4.1.25623.1.0.103866  

4553 Parasite Mothership Detect
Summary: The backdoor '4553' seems to be installed on this host, which indicates  it has been compromised.  Solution: Re-install this host.  CVSS Score: 9...
Test ID: 1.3.6.1.4.1.25623.1.0.11187  

SyGate Backdoor
Description:  SyGate engine remote controller seems to be running on this port.  It may be used by malicious users which are on the same subnet as this host to reconfigure the...
Test ID: 1.3.6.1.4.1.25623.1.0.10274  CVE: CVE-2000-0113  Bugtraq ID: 952  

XOOPS 'findusers.php' SQL Injection Vulnerability
Summary: XOOPS is prone to an SQL injection vulnerability.  Vulnerability Insight: The flaw exists due to XOOPS allowing remote authenticated administrators to execute  ...
Test ID: 1.3.6.1.4.1.25623.1.0.108137  CVE: CVE-2017-7290  

D-Link DNS/DNR Devices Multiple Vulnerabilities (SAP10383) - Active Check
Summary: Multiple D-Link DNS and DNR devices are prone to multiple  vulnerabilities.  Vulnerability Insight: The following vulnerabilities exist:   - CVE-2024...
Test ID: 1.3.6.1.4.1.25623.1.0.152068  

FTP server accepts a bad sequence of commands
Summary: The remote FTP service accepts commands in any order.  Vulnerability Insight: The remote server advertises itself as being a FTP server, but it accepts  command...
Test ID: 1.3.6.1.4.1.25623.1.0.80063  

ZTE ZXR10 Router < 3.00.40 Multiple Vulnerabilities
Summary: ZTE ZXR10 Router devices have a backdoor account with hardcoded credentials.  Vulnerability Impact: This issue may be exploited by a remote attacker to gain full ...
Test ID: 1.3.6.1.4.1.25623.1.0.107254  CVE: CVE-2017-10931  

OpenX 'flowplayer-3.1.1.min.js' Backdoor Vulnerability
Summary: OpenX is prone to a backdoor vulnerability.  Vulnerability Insight: The security issue is caused due to the distribution of a compromised OpenX Source source cod...
Test ID: 1.3.6.1.4.1.25623.1.0.103755  CVE: CVE-2013-4211  

Sitecom WLM-3500 Backdoor Accounts (HTTP)
Summary: Sitecom WLM-3500 routers contain an undocumented access  backdoor.  Vulnerability Insight: These hard-coded accounts are persistently stored inside the  d...
Test ID: 1.3.6.1.4.1.25623.1.0.803193  

FTP server does not accept any command
Summary: The remote FTP service is not working properly.  Vulnerability Insight: The remote server advertises itself as being a FTP server, but it does  not accept any c...
Test ID: 1.3.6.1.4.1.25623.1.0.80064  

Possible Backdoor
Summary: Look for potential backdoors.  Solution: Clean up the target host from the potential backdoor.  CVSS Score: 10.0  CVSS Vector: AV:N/AC:L...
Test ID: 1.3.6.1.4.1.25623.1.0.105238  

Port TCP:0 Open
Summary: TCP port 0 is open on the remote host. This is highly suspicious  as this TCP port is reserved and should not be used. This might be a backdoor (REx).  Solution:&nbs...
Test ID: 1.3.6.1.4.1.25623.1.0.18164  

Alcatel OmniSwitch 7700/7800 switches backdoor
Summary: The remote host seems to be a backdoored  Alcatel OmniSwitch 7700/7800.  Vulnerability Impact: An attacker can gain full access to any device  running AOS...
Test ID: 1.3.6.1.4.1.25623.1.0.11170  CVE: CVE-2002-1272  

MoonLit Virus Backdoor
Summary: The system is infected by the MoonLit virus,  the backdoor port is open.   Backdoor.Moonlit is a Trojan horse program that can download and execute files, and may a...
Test ID: 1.3.6.1.4.1.25623.1.0.15586  

Horde Groupware Webmail <= 5.2.22 RCE Vulnerability - Windows
Summary: Horde Groupware Webmail is prone to an authenticated remote  code execution (RCE) vulnerability.  Vulnerability Insight: Horde/Form/Type.php contains a vulnerab...
Test ID: 1.3.6.1.4.1.25623.1.0.142488  CVE: CVE-2019-9858  

WordPress MapPress Plugin < 2.53.9 Multiple Vulnerabilities
Summary: The WordPress plugin 'MapPress' is prone to multiple  vulnerabilities.  Vulnerability Insight: One vulnerability that allowed stored cross-site scripting  ...
Test ID: 1.3.6.1.4.1.25623.1.0.112735  CVE: CVE-2020-12077  

Netcore/Netis Devices Backdoor Access (UDP)
Summary: Netcore/Netis devices are exposing a backdoor access.  Vulnerability Insight: Affected devices include a backdoor service listening on UDP port 53413.  Vuln...
Test ID: 1.3.6.1.4.1.25623.1.0.105075  

LimeSurvey 2.05x < 2.06+ Multiple Vulnerabilities
Summary: LimeSurvey is prone to multiple vulnerabilities  Vulnerability Insight: The following vulnerabilities exist:   - Unauthenticated local file disclosure ...
Test ID: 1.3.6.1.4.1.25623.1.0.106064  

PHP File Manager Backdoor Vulnerability
Summary: PHP File Manager consists of a default backdoor user.  Vulnerability Insight: A default hidden user with admin permissions exists in the db/valid.users file. Thi...
Test ID: 1.3.6.1.4.1.25623.1.0.106034  

D-Link DIR-850L Rev.A1 < 1.20 / Rev.B1 < 2.20 XSS / Backdoor / Code Execution Vulnerabilities
Summary: D-Link DIR-850L devices suffer from cross-site scripting (XSS),  access bypass, backdoor, bruteforcing, information disclosure, remote code execution (RCE), and  denial ...
Test ID: 1.3.6.1.4.1.25623.1.0.107242  

Linux FTP backdoor
Description: There is a backdoor in the old ftp daemons of  Linux, which allows remote users to log in as 'NULL', with password 'NULL',  and to get root privileges over FTP.  ...
Test ID: 1.3.6.1.4.1.25623.1.0.10080  CVE: CVE-1999-0452  

CDK Detect
Description:  The remote host appears to be running CDK, which is a backdoor that can be  used to control your system.  To use it, an attacker just has to connect &n...
Test ID: 1.3.6.1.4.1.25623.1.0.10036  CVE: CVE-1999-0660  

CCleaner Cloud 'CCleaner.exe' Backdoor Trojan Vulnerability - Windows
Summary: CCleaner Cloud agent is prone to backdoor trojan installation vulnerability.  Vulnerability Insight: The flaw exists due to an unauthorized  modification of the...
Test ID: 1.3.6.1.4.1.25623.1.0.811780  

WordPress Captcha Plugin < 4.4.5 Backdoor Vulnerability
Summary: The WordPress plugin 'Captcha' is prone to a backdoor  vulnerability.  Affected Software/OS: WordPress Captcha plugin between version 4.3.6 and 4.4.4. &nbs...
Test ID: 1.3.6.1.4.1.25623.1.0.112155  

Bugbear.B web backdoor
Summary: Your system seems to be infected by the Bugbear.B virus  (its backdoor has been detected on port 81).  Solution: Use your favorite antivirus to disinfect your&n...
Test ID: 1.3.6.1.4.1.25623.1.0.11707  

D-Link Multiple Devices Backdoor
Summary: Various D-Link DSL routers are susceptible to a remote authentication bypass vulnerability.  Vulnerability Insight: By setting the User-Agent header to 'xmlset_r...
Test ID: 1.3.6.1.4.1.25623.1.0.103810  CVE: CVE-2013-6026  

D-Link DIR-850L Backdoor Account / Hardcoded Credentials (Telnet)
Summary: The D-Link DIR-850L router has a backdoor account with hardcoded credentials.  Vulnerability Insight: It was possible to login with the telnet credentials 'Alphanetwo...
Test ID: 1.3.6.1.4.1.25623.1.0.107301  CVE: CVE-2017-14421  

Fake FTP server accepts any command
Summary: The remote FTP service is not working properly  Vulnerability Insight: The remote server advertises itself as being a FTP server, but it accepts  any command, w...
Test ID: 1.3.6.1.4.1.25623.1.0.80062  

NetSphere Backdoor
Description: NetSphere is installed.   This backdoor allows anyone to partially take  control of the remote system.  An attacker may use this vulnerability to  ...
Test ID: 1.3.6.1.4.1.25623.1.0.10005  CVE: CVE-1999-0660  

Wollf backdoor detection
Summary: This host appears to be running Wollf on this port. Wollf Can be used as a  Backdoor which allows an intruder gain remote access to files on your computer.   If you...
Test ID: 1.3.6.1.4.1.25623.1.0.11881  

CCleaner 'CCleaner.exe' Backdoor Trojan Vulnerability - Windows
Summary: CCleaner is prone to backdoor trojan installation vulnerability.  Vulnerability Insight: The flaw exists due to an unauthorized  modification of the 'CCleaner.e...
Test ID: 1.3.6.1.4.1.25623.1.0.811779  

CVE-2020-28593
A unauthenticated backdoor exists in the configuration server functionality of Cosori Smart 5.8-Quart Air Fryer CS158-AF 1.1.0. A specially crafted JSON object can lead to code execution. An atta...

CVE-2019-10842
Arbitrary code execution (via backdoor code) was discovered in bootstrap-sass 3.2.0.3, when downloaded from rubygems.org. An unauthenticated attacker can craft the ___cfduid cookie value with bas...

CVE-2019-15224
The rest-client gem 1.6.10 through 1.6.13 for Ruby, as distributed on RubyGems.org, included a code-execution backdoor inserted by a third party. Versions <=1.6.9 and >=1.6.14 are unaffected.

CVE-2022-34059
The Sixfab-Tool in PyPI v0.0.2 to v0.0.3 was discovered to contain a code execution backdoor via the request package. This vulnerability allows attackers to access sensitive user information and ...

CVE-2019-12776
An issue was discovered on the ENTTEC Datagate MK2, Storm 24, Pixelator, and E-Streamer MK2 with firmware 70044_update_05032019-482. They include a hard-coded SSH backdoor for remote SSH and SCP ...

CVE-2022-42038
The d8s-ip-addresses package for Python, as distributed on PyPI, included a potential code-execution backdoor inserted by a third party. The backdoor is the democritus-csv package. The affected v...

CVE-2022-44054
The d8s-xml for python, as distributed on PyPI, included a potential code-execution backdoor inserted by a third party. A potential code execution backdoor inserted by third parties is the democr...

CVE-2021-40906
CheckMK Raw Edition software (versions 1.5.0 to 1.6.0) does not sanitise the input of a web service parameter that is in an unauthenticated zone. This Reflected XSS allows an attacker to open a b...

CVE-2022-40427
The d8s-domains for python, as distributed on PyPI, included a potential code-execution backdoor inserted by a third party. The backdoor is the democritus-networking package. The affected version...

CVE-2019-6548
GE Communicator, all versions prior to 4.0.517, contains two backdoor accounts with hardcoded credentials, which may allow control over the database. This service is inaccessible to attackers if ...

CVE-2018-6361
Easy Hosting Control Panel (EHCP) v0.37.12.b has XSS via the op parameter, as demonstrated by adding a backdoor FTP account.

CVE-2017-11436
D-Link DIR-615 before v20.12PTb04 has a second admin account with a 0x1 BACKDOOR value, which might allow remote attackers to obtain access via a TELNET connection.

CVE-2022-34055
The drxhello package in PyPI v0.0.1 was discovered to contain a code execution backdoor via the request package. This vulnerability allows attackers to access sensitive user information and digit...

CVE-2022-47209
A support user exists on the device and appears to be a backdoor for Technical Support staff. The default password for this account is “ support”  and cannot be changed by a u...

CVE-2013-6360
TRENDnet TS-S402 has a backdoor to enable TELNET.

CVE-2017-7462
Intellinet NFC-30ir IP Camera has a vendor backdoor that can allow a remote attacker access to a vendor-supplied CGI script in the web directory.

CVE-2022-38880
The d8s-urls for python, as distributed on PyPI, included a potential code-execution backdoor inserted by a third party. The affected version is 0.1.0.

CVE-2022-4093
SQL injection attacks can result in unauthorized access to sensitive data, such as passwords, credit card details, or personal user information. Many high-profile data breaches in recent years ha...

CVE-2022-32997
The RootInteractive package in PyPI v0.0.5 to v0.0.19b0 was discovered to contain a code execution backdoor via the request package. This vulnerability allows attackers to access sensitive user i...

CVE-2023-49963
DYMO LabelWriter Print Server through 2.366 contains a backdoor hard- coded password that could allow an attacker to take control.

CVE-2023-24107
hour_of_code_python_2015 commit 520929797b9ca43bb818b2e8f963fb2025459fa3 was discovered to contain a code execution backdoor via the request package (requirements.txt). This vulnerability allows ...

CVE-2014-3205
backupmgt/pre_connect_check.php in Seagate BlackArmor NAS contains a hard-coded password of '!~@##$$%FREDESWWSED' for a backdoor user.

CVE-2022-42039
The d8s-lists package for Python, as distributed on PyPI, included a potential code-execution backdoor inserted by a third party. The backdoor is the democritus-dicts package. The affected versio...

CVE-2019-7276
Optergy Proton/Enterprise devices allow Remote Root Code Execution via a Backdoor Console.

CVE-2017-10845
Wi-Fi STATION L-02F Software version V10g and earlier allows remote attackers to access the device with administrative privileges and perform unintended operations through a backdoor account.

CVE-2022-42040
The d8s-algorithms package for Python, as distributed on PyPI, included a potential code-execution backdoor inserted by a third party. The backdoor is the democritus-dicts package. The affected v...

CVE-2019-19033
Jalios JCMS 10 allows attackers to access any part of the website and the WebDAV server with administrative privileges via a backdoor account, by using any username and the hardcoded dev password...

CVE-2022-44050
The d8s-networking for python, as distributed on PyPI, included a potential code-execution backdoor inserted by a third party. A potential code execution backdoor inserted by third parties is the...

CVE-2019-17268
The omniauth-weibo-oauth2 gem 0.4.6 for Ruby, as distributed on RubyGems.org, included a code-execution backdoor inserted by a third party. Versions through 0.4.5, and 0.5.1 and later, are unaffe...

CVE-2021-33216
An issue was discovered in CommScope Ruckus IoT Controller 1.7.1.0 and earlier. An Undocumented Backdoor exists, allowing shell access via a developer account.

CVE-2022-40429
The d8s-ip-addresses for python, as distributed on PyPI, included a potential code-execution backdoor inserted by a third party. The backdoor is the democritus-networking package. The affected ve...

CVE-2022-40431
The d8s-pdfs for python, as distributed on PyPI, included a potential code-execution backdoor inserted by a third party. The backdoor is the democritus-networking package. The affected version is...

CVE-2022-33000
The ML-Scanner package in PyPI v0.1.0 to v0.1.5 was discovered to contain a code execution backdoor via the request package. This vulnerability allows attackers to access sensitive user informati...

CVE-2009-5025
A backdoor (aka BMSA-2009-07) was found in PyForum v1.0.3 where an attacker who knows a valid user email could force a password reset on behalf of that user.

CVE-2015-2882
Philips In.Sight B120/37 has a password of b120root for the backdoor root account, a password of /ADMIN/ for the backdoor admin account, a password of merlin for the backdoor mg3500 account, a pa...

CVE-2021-40903
A vulnerability in Antminer Monitor 0.50.0 exists because of backdoor or misconfiguration inside a settings file in flask server. Settings file has a predefined secret string, which would be rand...

CVE-2022-40432
The d8s-strings for python, as distributed on PyPI, included a potential code-execution backdoor inserted by a third party. The backdoor is the democritus-hypothesis package. The affected version...

CVE-2017-7290
SQL injection vulnerability in XOOPS 2.5.7.2 and other versions before 2.5.8.1 allows remote authenticated administrators to execute arbitrary SQL commands via the url parameter to findusers.php....

CVE-2022-46609
Python3-RESTfulAPI commit d9907f14e9e25dcdb54f5b22252b0e9452e3970e and e772e0beee284c50946e94c54a1d43071ca78b74 was discovered to contain a code execution backdoor via the request package. This v...

CVE-2021-36563
The CheckMK management web console (versions 1.5.0 to 2.0.0) does not sanitise user input in various parameters of the WATO module. This allows an attacker to open a backdoor on the device with H...

CVE-2017-8218
vsftpd on TP-Link C2 and C20i devices through firmware 0.9.1 4.2 v0032.0 Build 160706 Rel.37961n has a backdoor admin account with the 1234 password, a backdoor guest account with the guest passw...

CVE-2010-0103
UsbCharger.dll in the Energizer DUO USB battery charger software contains a backdoor that is implemented through the Arucer.dll file in the %WINDIR%\system32 directory, which allows remote attack...

CVE-2023-26243
An issue was discovered in the Hyundai Gen5W_L in-vehicle infotainment system AE_E_PE_EUR.S5W_L001.001.211214. The decryption binary used to decrypt firmware files has an information leak that al...

CVE-2004-0260
The AddToMailingList function in CactuSoft CactuShop 5.0 Lite contains a backdoor that allows remote attackers to delete arbitrary files via an email address that starts with |||.

CVE-2022-42042
The d8s-networking package for Python, as distributed on PyPI, included a potential code-execution backdoor inserted by a third party. The backdoor is the democritus-hashes package. The affected ...

CVE-2022-40811
The d8s-urls for python, as distributed on PyPI, included a potential code-execution backdoor inserted by a third party. The backdoor is the democritus-file-system package. The affected version i...

CVE-2022-41380
The d8s-yaml package for Python, as distributed on PyPI, included a potential code-execution backdoor inserted by a third party. The backdoor is the democritus-file-system package. The affected v...

CVE-2022-41384
The d8s-domains package for Python, as distributed on PyPI, included a potential code-execution backdoor inserted by a third party. The backdoor is the democritus-urls package. The affected versi...

CVE-2022-34056
The Watertools package in PyPI v0.0.0 was discovered to contain a code execution backdoor via the request package. This vulnerability allows attackers to access sensitive user information and dig...

CVE-2022-44051
The d8s-stats for python, as distributed on PyPI, included a potential code-execution backdoor inserted by a third party. A potential code execution backdoor inserted by third parties is the demo...



© 1998-2025 E-Soft Inc. All rights reserved.