S4E just found a medium-severity finding from internal ip disclosure vulnerability scanner
PlatformPlansPartners
Resources
ToolsBlogDocs
Sign Up →
medium·Product Based Web Vulnerabilities·Updated Jan 3, 2024

CVE-2018-19892 Scanner

CVE-2018-19892 scanner - Cross-Site Scripting (XSS) vulnerability in DomainMOD

Est. Time~10 seconds
Scan TypeSingle Scan
Targetsdomain, ipv4, subdomain
CostFree
2.6k
Times Used
continuous scan runs
4.2k
Continuously Checked
assets under CS
0
Vulnerabilities Found
confirmed findings
References
CVECVE-2018-19892
4.8
CVSS

DomainMOD through 4.11.01 has XSS via the admin/dw/add-server.php DisplayName, HostName, or UserName field.

Attack Vector
-
Privileges Req.
-
User Interaction
-
Affected
n/aby n/a
n/a
Updated Aug 21, 2026View on NVD →
Detail

DomainMOD is a free and open-source domain name management software that helps users manage their domains, servers, and hosting accounts. It provides a web-based interface that allows users to organize and manage their domains easily. The software can manage domain registrations, DNS records, and server configurations.

CVE-2018-19892 is a vulnerability detected in DomainMOD through 4.11.01, which allows attackers to inject malicious code into the DisplayName, HostName or UserName fields in the admin/dw/add-server.php section, leading to cross-site scripting (XSS) attacks. When exploited, it allows attackers to execute arbitrary scripts in the victim's web browser, steal sensitive information, create fake login pages, or hijack user sessions.

Exploiting the CVE-2018-19892 vulnerability in DomainMOD can lead to serious consequences, including unauthorized access to sensitive information, the possibility of escalating privileges, and even taking over control of the affected servers. This vulnerability can also expose users to Phishing attacks and other forms of cybercrime, leading to financial losses and reputational damage.

At s4e.io, we specialize in providing robust and reliable cybersecurity solutions that help businesses and individuals protect their digital assets. Our platform provides comprehensive vulnerability scanning, reporting, and remediation services that help you stay ahead of the evolving threat landscape. With s4e.io, you can easily and quickly learn about vulnerabilities in your digital assets, helping you take proactive measures to mitigate the risk of cyber threats.

 

REFERENCES

Solution Advice

To protect yourself against the CVE-2018-19892 vulnerability in DomainMOD, here are some precautions to take:

  • Update DomainMOD to the latest version or remove it from your system if you are not using it.
  • Employ a regular vulnerability scanning regimen to detect potential vulnerabilities in your network infrastructure and web applications.
  • Use a security-focused web application firewall (WAF) to protect against known and unknown threats.
  • Implement strict input validation and sanitization rules to prevent the injection of malicious code via user input.
  • Regularly monitor and analyze your server logs to detect potential attacks and anomalous activity.

Get AI-powered remediation steps tailored to your asset.

Try AI Solutions →

Check your infrastructure.
Right now.

11,000+ scanners. Free to start. No credit card required.

CVE-2018-19892 scanner - Cross-Site Scripting (XSS) vulnerability in DomainMOD | S4E