S4E just found a high-severity finding from ssl sweet32 vulnerability checker
PlatformPlansPartners
Resources
ToolsBlogDocs
Sign Up →
medium·Product Based Web Vulnerabilities·Updated Jan 3, 2024

CVE-2018-19137 Scanner

CVE-2018-19137 scanner - Cross-Site Scripting (XSS) vulnerability in DomainMOD

Est. Time~10 seconds
Scan TypeSingle Scan
Targetsdomain, ipv4, subdomain
CostFree
2.5k
Times Used
continuous scan runs
4.2k
Continuously Checked
assets under CS
0
Vulnerabilities Found
confirmed findings
References
CVECVE-2018-19137
6.1
CVSS

DomainMOD through 4.11.01 has XSS via the assets/edit/ip-address.php ipid parameter.

Attack Vector
-
Privileges Req.
-
User Interaction
-
Affected
n/aby n/a
n/a
Updated Aug 21, 2026View on NVD →
Detail

DomainMOD is a free open-source software used to manage and organize domain name portfolios. It is designed to simplify the often-complex task of managing domains by providing an easy-to-use interface for monitoring, analyzing, and organizing them. At its core, DomainMOD is designed to help users manage the lifecycle of a domain name, from registration to renewal and everything in between. It also provides financial and statistical analysis, offering a complete overview of the domain portfolio.

The CVE-2018-19137 vulnerability detected in DomainMOD is a cross-site scripting (XSS) vulnerability that can be exploited via the assets/edit/ip-address.php ipid parameter. This vulnerability could allow an attacker to execute malicious code in a victim's web browser, potentially leading to the theft of sensitive data and other malicious activities.

When exploited, this vulnerability can lead to serious security risks, including the potential for unauthorized access to sensitive information, such as login credentials, financial data, and personal user information. It can also result in the installation of malware or other malicious software, which can lead to further harm to the system or network.

Thanks to the pro features of the s4e.io platform, readers of this article can easily and quickly learn about vulnerabilities in their digital assets. This platform offers comprehensive threat intelligence and vulnerability management tools, allowing users to identify, prioritize, and remediate security issues before they can be exploited. Users can also stay up-to-date with the latest security threats and trends, ensuring that their digital assets are protected against the latest threats. Overall, by utilizing the benefits of the s4e.io platform, users can ensure the safety and security of their digital assets in an ever-evolving threat landscape.

 

REFERENCES

Solution Advice

To protect against this vulnerability, several precautions can be taken, including:

  • Keeping software up-to-date and applying the latest security patches
  • Regularly conducting security audits and vulnerability assessments
  • Ensuring that all inputs to DomainMOD are sanitized and validated to prevent injection attacks
  • Using a web application firewall to add an additional layer of protection
  • Running DomainMOD in a secure and isolated environment, such as a virtual machine

Get AI-powered remediation steps tailored to your asset.

Try AI Solutions →

Check your infrastructure.
Right now.

11,000+ scanners. Free to start. No credit card required.

CVE-2018-19137 scanner - Cross-Site Scripting (XSS) vulnerability in DomainMOD | S4E