Last Seen: 2025-04-24

GeneralInformation

web01.wandfluh.opsserver.ch
www.wandfluh-china.com
www.wandfluh-us.com
www.wandfluh.at
www.wandfluh.ch
www.wandfluh.com
www.wandfluh.de
www.wandfluh.fr
www.wapro.ch

WebTechnologies

JavaScript libraries
Programming languages
Security
Tag managers

OpenPorts

21 / tcp
128993486 | 2025-04-23T11:20:48.195428
22 / tcp
1641976472 | 2025-04-19T22:50:41.914685
80 / tcp
-1965153966 | 2025-04-24T10:26:38.084629
443 / tcp
1537875659 | 2025-04-24T14:59:21.683170

Vulnerabilities

Note: the device may not be impacted by all of these issues. The vulnerabilities are implied based on the software and version.

2020(2)
CVE-2020-11023
6.9In jQuery versions greater than or equal to 1.0.3 and before 3.5.0, passing HTML containing <option> elements from untrusted sources - even after sanitizing it - to one of jQuery's DOM manipulation methods (i.e. .html(), .append(), and others) may execute untrusted code. This problem is patched in jQuery 3.5.0.
CVE-2020-11022
6.9In jQuery versions greater than or equal to 1.2 and before 3.5.0, passing HTML from untrusted sources - even after sanitizing it - to one of jQuery's DOM manipulation methods (i.e. .html(), .append(), and others) may execute untrusted code. This problem is patched in jQuery 3.5.0.
2019(1)
CVE-2019-11358
6.1jQuery before 3.4.0, as used in Drupal, Backdrop CMS, and other products, mishandles jQuery.extend(true, {}, ...) because of Object.prototype pollution. If an unsanitized source object contained an enumerable __proto__ property, it could extend the native Object.prototype.
2015(1)
CVE-2015-9251
6.1jQuery before 3.0.0 is vulnerable to Cross-site Scripting (XSS) attacks when a cross-domain Ajax request is performed without the dataType option, causing text/javascript responses to be executed.



Contact Us

Shodan ® - All rights reserved