Re: found on page via Retire.Js
jquery-ui-dialog 1.9.2 Found in -https://urlquery.net/static/org/javascript/jquery-ui-1.9.2.custom.min.js
Vulnerability info:
Medium CVE-2010-5312 6016 Title cross-site scripting vulnerability
High CVE-2016-7103 281 XSS Vulnerability on closeText option
jquery-ui-tooltip 1.9.2 Found in -https://urlquery.net/static/org/javascript/jquery-ui-1.9.2.custom.min.js
Vulnerability info:
High CVE-2012-6662 8859 Autocomplete cross-site scripting vulnerability 12
jquery 1.8.3 Found in -https://urlquery.net/static/org/javascript/jquery-1.8.3.js
Vulnerability info:
Medium CVE-2012-6708 11290 Selector interpreted as HTML 123
Medium 2432 3rd party CORS request may execute CVE-2015-9251 1234
Medium CVE-2015-9251 11974 parseHTML() executes scripts in event handlers 123
Medium CVE-2019-11358 jQuery before 3.4.0, as used in Drupal, Backdrop CMS, and other products, mishandles jQuery.extend(true, {}, …) because of Object.prototype pollution
Not from that main url, but again from JQuery: Results from scanning URL: -https://urlquery.net/static/org/javascript/jquery-1.8.3.js
Number of sources found: 117 ; number of sinks found: 92
This being blocked for me via uMatrix: -https://adservice.google.nl/adsid/integrator.js?domain=urlquery.net
gives a insecure connection to: -https://kreditkavbanke.ru/wp-content/themes/soledad/js/libs-script.min.js?ver=1.0
Number of sources found: 32 ; number of sinks found: 13
&
Results from scanning URL: -https://kreditkavbanke.ru/wp-content/themes/soledad/js/main.js?ver=1.0
Number of sources found: 41 ; number of sinks found: 17
Probably because of
Results from scanning URL: htxps://kreditkavbanke.ru
Number of sources found: 28
Number of sinks found: 108
polonus (volunteer 3rd party cold reconnaissance website security analyst and website error-hunter)