Vulnerability index

Browse CVEs

19 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Domainmod MEDIUM 6.6
CVE-2024-48622

A cross-site scripting (XSS) issue in DomainMOD below v4.12.0 allows remote attackers to inject JavaScript code via admin/domain-fields/edit.php and …

Fix: 4.12.0+
Fix from $1,600 2024-10-15
Domainmod MEDIUM 5.3
CVE-2024-48623

In queue\index.php of DomainMOD below v4.12.0, the list_id and domain_id parameters in the GET request can be exploited to cause a reflected Cross Si…

Fix: 4.12.0+
Fix from $1,600 2024-10-15
Domainmod MEDIUM 5.3
CVE-2024-48624

In segments\edit.php of DomainMOD below v4.12.0, the segid parameter in the GET request can be exploited to cause a reflected Cross Site Scripting (X…

Fix: 4.12.0+
Fix from $1,600 2024-10-15
Domainmod MEDIUM 5.4
CVE-2020-20988

A cross site scripting (XSS) vulnerability in the /domains/cost-by-owner.php component of Domainmod 4.13 allows attackers to execute arbitrary web sc…

No fix yet
Fix from $1,600 2021-08-12
Domainmod MEDIUM 5.4
CVE-2020-20990

A cross site scripting (XSS) vulnerability in the /segments/edit.php component of Domainmod 4.13 allows attackers to execute arbitrary web scripts or…

No fix yet
Fix from $1,600 2021-08-12
Domainmod CRITICAL 9.8
CVE-2020-35358

DomainMOD domainmod-v4.15.0 is affected by an insufficient session expiration vulnerability. On changing a password, both sessions using the changed …

No fix yet
Fix from $2,300 2021-03-15
Domainmod HIGH 7.5
CVE-2019-9080

DomainMOD before 4.14.0 uses MD5 without a salt for password storage.

Fix: 4.14.0+
Fix from $1,950 2020-10-20
Domainmod CRITICAL 9.8
CVE-2020-12735

reset.php in DomainMOD 4.13.0 uses insufficient entropy for password reset requests, leading to account takeover.

No fix yet
Fix from $2,300 2020-05-08
Domainmod MEDIUM 6.1
CVE-2019-15811EPSS 7%

In DomainMOD through 4.13, the parameter daterange in the file reporting/domains/cost-by-month.php has XSS.

Fix: after 4.13.0
Fix from $1,600 2019-08-29
Domainmod HIGH 8.8
CVE-2019-1010094

domainmod v4.10.0 is affected by: Cross Site Request Forgery (CSRF). The impact is: There is a CSRF vulnerability that can change admin password. The…

No fix yet
Fix from $1,950 2019-07-18
Domainmod HIGH 8.8
CVE-2019-1010095

DomainMOD v4.10.0 is affected by: Cross Site Request Forgery (CSRF). The impact is: There is a CSRF vulnerability that can add the administrator acco…

No fix yet
Fix from $1,950 2019-07-18
Domainmod HIGH 8.8
CVE-2019-1010096

DomainMOD v4.10.0 is affected by: Cross Site Request Forgery (CSRF). The impact is: There is a CSRF vulnerability that can change the read-only user …

No fix yet
Fix from $1,950 2019-07-18
Domainmod MEDIUM 5.4
CVE-2018-19750

DomainMOD through 4.11.01 has XSS via the admin/domain-fields/ notes field in an Add Custom Field action for Custom Domain Fields.

Fix: after 4.11.01
Fix from $1,600 2018-11-29
Domainmod MEDIUM 6.1
CVE-2018-19136EPSS 7%

DomainMOD through 4.11.01 has XSS via the assets/edit/registrar-account.php raid parameter.

Fix: after 4.11.01
Fix from $1,600 2018-11-09
Domainmod MEDIUM 6.1
CVE-2018-19137

DomainMOD through 4.11.01 has XSS via the assets/edit/ip-address.php ipid parameter.

Fix: after 4.11.01
Fix from $1,600 2018-11-09
Domainmod MEDIUM 5.4
CVE-2018-11558

DomainMod 4.10.0 has Stored XSS in the "/settings/profile/index.php" new_first_name parameter.

No fix yet
Fix from $1,600 2018-05-30
Domainmod MEDIUM 5.4
CVE-2018-11559

DomainMod 4.10.0 has Stored XSS in the "/settings/profile/index.php" new_last_name parameter.

No fix yet
Fix from $1,600 2018-05-30
Domainmod MEDIUM 6.1
CVE-2018-11404

DomainMod v4.09.03 has XSS via the assets/edit/ssl-provider-account.php sslpaid parameter.

No fix yet
Fix from $1,600 2018-05-24
Domainmod MEDIUM 5.4
CVE-2018-11403

DomainMod v4.09.03 has XSS via the assets/edit/account-owner.php oid parameter.

No fix yet
Fix from $1,600 2018-05-24