Microsoft-IIS 10.0
tcp/443
Exposing Swagger/OpenAPI documentation is primarily a risk if your API has underlying security flaws, as it gives attackers a precise roadmap to find them.
Those detail every endpoint, parameter, and data model, making it easier to discover and exploit vulnerabilities like broken access control or injection points.
While a perfectly secure API mitigates the danger, protecting your documentation is a critical layer of defense that forces attackers to work without a map.
Severity: info
Fingerprint: 5733ddf49ff49cd1f3d88d6088d4b35fd462d0c430726bf6beea2903a4d31a2d
Public Swagger UI/API detected at path: /swagger/v1/swagger.json - sample paths:
GET /CarHistory/{apiKey}
GET /CarHistory/{apiKey}/All
GET /CarHistory/{apiKey}/{pageNumber}/{countOnPage}
GET /CarServices/{apiKey}
GET /CarServices/{apiKey}/All
GET /CarServices/{apiKey}/{pageNumber}/{countOnPage}
GET /Cars/{apiKey}
GET /Cars/{apiKey}/All
GET /Cars/{apiKey}/{pageNumber}/{countOnPage}
GET /CostCenterHistory/{apiKey}
GET /CostCenterHistory/{apiKey}/All
GET /CostCenterHistory/{apiKey}/{pageNumber}/{countOnPage}
GET /Drivers/{apiKey}
GET /Drivers/{apiKey}/All
GET /Drivers/{apiKey}/{pageNumber}/{countOnPage}
GET /Incidents/{apiKey}
GET /Incidents/{apiKey}/{pageNumber}/{countOnPage}
GET /MileageHistory/{apiKey}
GET /MileageHistory/{apiKey}/All
GET /MileageHistory/{apiKey}/{pageNumber}/{countOnPage}
POST /CarHistory/{apiKey}/Search/{pageNumber}/{countOnPage}
POST /CarServices/{apiKey}/Search/{pageNumber}/{countOnPage}
POST /Cars/{apiKey}/Search/{pageNumber}/{countOnPage}
POST /CostCenterHistory/{apiKey}/Search/{pageNumber}/{countOnPage}
POST /Drivers/{apiKey}/Search/{pageNumber}/{countOnPage}
POST /MileageHistory/{apiKey}/Search/{pageNumber}/{countOnPage}
Open service 20.50.2.35:443 · api.mobexo.de
2026-01-09 08:29
HTTP/1.1 301 Moved Permanently Content-Length: 0 Connection: close Date: Fri, 09 Jan 2026 08:30:18 GMT Server: Microsoft-IIS/10.0 Location: index.html Set-Cookie: ARRAffinity=95aa365019ac512b58ee1e0cd27be0dc8a7428fb1ebebc61ba1274ffc14ea64d;Path=/;HttpOnly;Secure;Domain=api.mobexo.de Set-Cookie: ARRAffinitySameSite=95aa365019ac512b58ee1e0cd27be0dc8a7428fb1ebebc61ba1274ffc14ea64d;Path=/;HttpOnly;SameSite=None;Secure;Domain=api.mobexo.de X-Powered-By: ASP.NET
Open service 20.50.2.35:443 · api.mobexo.de
2026-01-02 10:26
HTTP/1.1 301 Moved Permanently Content-Length: 0 Connection: close Date: Fri, 02 Jan 2026 10:26:06 GMT Server: Microsoft-IIS/10.0 Location: index.html Set-Cookie: ARRAffinity=c5d8c21d2f8376f630cabc60182b2ff2d349eef5ec3dc9194c46a2ac84a416eb;Path=/;HttpOnly;Secure;Domain=api.mobexo.de Set-Cookie: ARRAffinitySameSite=c5d8c21d2f8376f630cabc60182b2ff2d349eef5ec3dc9194c46a2ac84a416eb;Path=/;HttpOnly;SameSite=None;Secure;Domain=api.mobexo.de X-Powered-By: ASP.NET
Open service 20.50.2.35:443 · api.mobexo.de
2025-12-22 09:26
HTTP/1.1 301 Moved Permanently Content-Length: 0 Connection: close Date: Mon, 22 Dec 2025 09:26:21 GMT Server: Microsoft-IIS/10.0 Location: index.html Set-Cookie: ARRAffinity=c5d8c21d2f8376f630cabc60182b2ff2d349eef5ec3dc9194c46a2ac84a416eb;Path=/;HttpOnly;Secure;Domain=api.mobexo.de Set-Cookie: ARRAffinitySameSite=c5d8c21d2f8376f630cabc60182b2ff2d349eef5ec3dc9194c46a2ac84a416eb;Path=/;HttpOnly;SameSite=None;Secure;Domain=api.mobexo.de X-Powered-By: ASP.NET
Open service 20.50.2.35:443 · api.mobexo.de
2025-12-20 12:49
HTTP/1.1 301 Moved Permanently Content-Length: 0 Connection: close Date: Sat, 20 Dec 2025 12:49:02 GMT Server: Microsoft-IIS/10.0 Location: index.html Set-Cookie: ARRAffinity=c5d8c21d2f8376f630cabc60182b2ff2d349eef5ec3dc9194c46a2ac84a416eb;Path=/;HttpOnly;Secure;Domain=api.mobexo.de Set-Cookie: ARRAffinitySameSite=c5d8c21d2f8376f630cabc60182b2ff2d349eef5ec3dc9194c46a2ac84a416eb;Path=/;HttpOnly;SameSite=None;Secure;Domain=api.mobexo.de X-Powered-By: ASP.NET