Yoast SEO Plugin v1.14.15 has a xss vulnerability due to lack of search
sanitation.
Exploit:
This can be exploited with a browser and is usually executed inside the
search parameter of the website.
Proof of concept:
http://5linx.com/?s=">alert(document.cookie);
Description: WordPress SEO by Yoast Plugin for WordPress contains a flaw that is due to the program failing to properly restrict access to users. This may allow a remote attacker to bypass restrictions placed on the 'reset settings' feature.
Classification:
Location: Remote / Network Access
Attack Type: Input Manipulation
Impact: Loss of Integrity
Solution: Solution Unknown
Exploit: Exploit Private
Disclosure: Vendor Verified, Third-party Verified
OSVDB: Web Related
Подскажите, опасны ли они?
Ещё немного информации от nmap, по открытым портам (17):