nginx 1.18.0
tcp/443 tcp/80
The following Moodle application is publicly accessible and looks out-dated :
It is highly recommended to update to a safe version as soon as possible since multiple CVEs allow remote attackers to craft XSS attacks leading to code execution on the server.
If the application was already patched, reloading the web server to clear the PHP opcache will fix issue.
Reference:
Severity: high
Fingerprint: 0b591a20d83e9bbda3370ce58008084480080844800808448008084480080844
Found vulnerable Moodle application: Affected by CVE-2023-30943
Open service 35.179.22.171:443 · barclayjonesdemo.moodle.tituslearning.com
2024-12-22 01:19
HTTP/1.1 200 OK Server: nginx/1.18.0 (Ubuntu) Date: Sun, 22 Dec 2024 01:19:51 GMT Content-Type: text/html; charset=utf-8 Transfer-Encoding: chunked Connection: close Set-Cookie: MoodleSession=af3bbtqf4hatps6n4l9d3lhrck; path=/; secure; HttpOnly Content-Language: en Content-Script-Type: text/javascript Content-Style-Type: text/css X-UA-Compatible: IE=edge Cache-Control: no-store, no-cache, must-revalidate Cache-Control: post-check=0, pre-check=0, no-transform Pragma: no-cache Expires: Mon, 20 Aug 1969 09:23:00 GMT Last-Modified: Sun, 22 Dec 2024 01:19:51 GMT Accept-Ranges: none X-Frame-Options: sameorigin Strict-Transport-Security: max-age=31536000; includeSubDomains X-Content-Type-Options: nosniff Referrer-Policy: origin Permissions-Policy: accelerometer=(), geolocation=(), gyroscope=(), magnetometer=(), payment=(), usb=()
Open service 35.179.22.171:443 · barclayjonesdemo.moodle.tituslearning.com
2024-12-20 01:52
HTTP/1.1 200 OK Server: nginx/1.18.0 (Ubuntu) Date: Fri, 20 Dec 2024 01:52:59 GMT Content-Type: text/html; charset=utf-8 Transfer-Encoding: chunked Connection: close Set-Cookie: MoodleSession=9pas2audmgpchapr7fqjogpjlc; path=/; secure; HttpOnly Content-Language: en Content-Script-Type: text/javascript Content-Style-Type: text/css X-UA-Compatible: IE=edge Cache-Control: no-store, no-cache, must-revalidate Cache-Control: post-check=0, pre-check=0, no-transform Pragma: no-cache Expires: Mon, 20 Aug 1969 09:23:00 GMT Last-Modified: Fri, 20 Dec 2024 01:52:59 GMT Accept-Ranges: none X-Frame-Options: sameorigin Strict-Transport-Security: max-age=31536000; includeSubDomains X-Content-Type-Options: nosniff Referrer-Policy: origin Permissions-Policy: accelerometer=(), geolocation=(), gyroscope=(), magnetometer=(), payment=(), usb=()
Open service 35.179.22.171:443 · barclayjonesdemo.moodle.tituslearning.com
2024-12-18 02:21
HTTP/1.1 200 OK Server: nginx/1.18.0 (Ubuntu) Date: Wed, 18 Dec 2024 02:21:42 GMT Content-Type: text/html; charset=utf-8 Transfer-Encoding: chunked Connection: close Set-Cookie: MoodleSession=fh49ijbrnipg8lbflpg8ikbs5d; path=/; secure; HttpOnly Content-Language: en Content-Script-Type: text/javascript Content-Style-Type: text/css X-UA-Compatible: IE=edge Cache-Control: no-store, no-cache, must-revalidate Cache-Control: post-check=0, pre-check=0, no-transform Pragma: no-cache Expires: Mon, 20 Aug 1969 09:23:00 GMT Last-Modified: Wed, 18 Dec 2024 02:21:42 GMT Accept-Ranges: none X-Frame-Options: sameorigin Strict-Transport-Security: max-age=31536000; includeSubDomains X-Content-Type-Options: nosniff Referrer-Policy: origin Permissions-Policy: accelerometer=(), geolocation=(), gyroscope=(), magnetometer=(), payment=(), usb=()
Open service 35.179.22.171:443 · barclayjonesdemo.moodle.tituslearning.com
2024-12-16 00:26
HTTP/1.1 200 OK Server: nginx/1.18.0 (Ubuntu) Date: Mon, 16 Dec 2024 00:26:12 GMT Content-Type: text/html; charset=utf-8 Transfer-Encoding: chunked Connection: close Set-Cookie: MoodleSession=lhrh2mdirbub3q7h38rl3o79q3; path=/; secure; HttpOnly Content-Language: en Content-Script-Type: text/javascript Content-Style-Type: text/css X-UA-Compatible: IE=edge Cache-Control: no-store, no-cache, must-revalidate Cache-Control: post-check=0, pre-check=0, no-transform Pragma: no-cache Expires: Mon, 20 Aug 1969 09:23:00 GMT Last-Modified: Mon, 16 Dec 2024 00:26:12 GMT Accept-Ranges: none X-Frame-Options: sameorigin Strict-Transport-Security: max-age=31536000; includeSubDomains X-Content-Type-Options: nosniff Referrer-Policy: origin Permissions-Policy: accelerometer=(), geolocation=(), gyroscope=(), magnetometer=(), payment=(), usb=()
Open service 35.179.22.171:443 · barclayjonesdemo.moodle.tituslearning.com
2024-12-14 00:28
HTTP/1.1 200 OK Server: nginx/1.18.0 (Ubuntu) Date: Sat, 14 Dec 2024 00:28:52 GMT Content-Type: text/html; charset=utf-8 Transfer-Encoding: chunked Connection: close Set-Cookie: MoodleSession=0ekfnepov788hngq3ugui1mofa; path=/; secure; HttpOnly Content-Language: en Content-Script-Type: text/javascript Content-Style-Type: text/css X-UA-Compatible: IE=edge Cache-Control: no-store, no-cache, must-revalidate Cache-Control: post-check=0, pre-check=0, no-transform Pragma: no-cache Expires: Mon, 20 Aug 1969 09:23:00 GMT Last-Modified: Sat, 14 Dec 2024 00:28:52 GMT Accept-Ranges: none X-Frame-Options: sameorigin Strict-Transport-Security: max-age=31536000; includeSubDomains X-Content-Type-Options: nosniff Referrer-Policy: origin Permissions-Policy: accelerometer=(), geolocation=(), gyroscope=(), magnetometer=(), payment=(), usb=()
Open service 35.179.22.171:443 · barclayjonesdemo.moodle.tituslearning.com
2024-12-12 01:35
HTTP/1.1 200 OK Server: nginx/1.18.0 (Ubuntu) Date: Thu, 12 Dec 2024 01:35:37 GMT Content-Type: text/html; charset=utf-8 Transfer-Encoding: chunked Connection: close Set-Cookie: MoodleSession=afom5o3lehrie88l656mhapgcc; path=/; secure; HttpOnly Content-Language: en Content-Script-Type: text/javascript Content-Style-Type: text/css X-UA-Compatible: IE=edge Cache-Control: no-store, no-cache, must-revalidate Cache-Control: post-check=0, pre-check=0, no-transform Pragma: no-cache Expires: Mon, 20 Aug 1969 09:23:00 GMT Last-Modified: Thu, 12 Dec 2024 01:35:37 GMT Accept-Ranges: none X-Frame-Options: sameorigin Strict-Transport-Security: max-age=31536000; includeSubDomains X-Content-Type-Options: nosniff Referrer-Policy: origin Permissions-Policy: accelerometer=(), geolocation=(), gyroscope=(), magnetometer=(), payment=(), usb=()
Open service 35.179.22.171:443 · barclayjonesdemo.moodle.tituslearning.com
2024-12-02 03:22
HTTP/1.1 200 OK Server: nginx/1.18.0 (Ubuntu) Date: Mon, 02 Dec 2024 03:22:39 GMT Content-Type: text/html; charset=utf-8 Transfer-Encoding: chunked Connection: close Set-Cookie: MoodleSession=ah0063hmjgptcshrqq5iga91r6; path=/; secure; HttpOnly Content-Language: en Content-Script-Type: text/javascript Content-Style-Type: text/css X-UA-Compatible: IE=edge Cache-Control: no-store, no-cache, must-revalidate Cache-Control: post-check=0, pre-check=0, no-transform Pragma: no-cache Expires: Mon, 20 Aug 1969 09:23:00 GMT Last-Modified: Mon, 02 Dec 2024 03:22:39 GMT Accept-Ranges: none X-Frame-Options: sameorigin Strict-Transport-Security: max-age=31536000; includeSubDomains X-Content-Type-Options: nosniff Referrer-Policy: origin Permissions-Policy: accelerometer=(), geolocation=(), gyroscope=(), magnetometer=(), payment=(), usb=()
Open service 35.179.22.171:443 · barclayjonesdemo.moodle.tituslearning.com
2024-11-30 02:31
HTTP/1.1 200 OK Server: nginx/1.18.0 (Ubuntu) Date: Sat, 30 Nov 2024 02:31:45 GMT Content-Type: text/html; charset=utf-8 Transfer-Encoding: chunked Connection: close Set-Cookie: MoodleSession=4g9vf4lmhb1eij8ietg244kkn9; path=/; secure; HttpOnly Content-Language: en Content-Script-Type: text/javascript Content-Style-Type: text/css X-UA-Compatible: IE=edge Cache-Control: no-store, no-cache, must-revalidate Cache-Control: post-check=0, pre-check=0, no-transform Pragma: no-cache Expires: Mon, 20 Aug 1969 09:23:00 GMT Last-Modified: Sat, 30 Nov 2024 02:31:45 GMT Accept-Ranges: none X-Frame-Options: sameorigin Strict-Transport-Security: max-age=31536000; includeSubDomains X-Content-Type-Options: nosniff Referrer-Policy: origin Permissions-Policy: accelerometer=(), geolocation=(), gyroscope=(), magnetometer=(), payment=(), usb=()
Open service 35.179.22.171:80 · barclayjonesdemo.moodle.tituslearning.com
2024-11-29 22:17
HTTP/1.1 301 Moved Permanently Server: nginx/1.18.0 (Ubuntu) Date: Fri, 29 Nov 2024 22:17:25 GMT Content-Type: text/html Content-Length: 178 Connection: close Location: https://barclayjonesdemo.moodle.tituslearning.com/ Page title: 301 Moved Permanently <html> <head><title>301 Moved Permanently</title></head> <body> <center><h1>301 Moved Permanently</h1></center> <hr><center>nginx/1.18.0 (Ubuntu)</center> </body> </html>
Open service 35.179.22.171:443 · barclayjonesdemo.moodle.tituslearning.com
2024-11-29 22:17
HTTP/1.1 200 OK Server: nginx/1.18.0 (Ubuntu) Date: Fri, 29 Nov 2024 22:17:26 GMT Content-Type: text/html; charset=utf-8 Transfer-Encoding: chunked Connection: close Set-Cookie: MoodleSession=3ec5r32942l0icptt6ol29aulh; path=/; secure; HttpOnly Content-Language: en Content-Script-Type: text/javascript Content-Style-Type: text/css X-UA-Compatible: IE=edge Cache-Control: no-store, no-cache, must-revalidate Cache-Control: post-check=0, pre-check=0, no-transform Pragma: no-cache Expires: Mon, 20 Aug 1969 09:23:00 GMT Last-Modified: Fri, 29 Nov 2024 22:17:26 GMT Accept-Ranges: none X-Frame-Options: sameorigin Strict-Transport-Security: max-age=31536000; includeSubDomains X-Content-Type-Options: nosniff Referrer-Policy: origin Permissions-Policy: accelerometer=(), geolocation=(), gyroscope=(), magnetometer=(), payment=(), usb=()
Open service 35.179.22.171:443 · barclayjonesdemo.moodle.tituslearning.com
2024-11-28 02:44
HTTP/1.1 200 OK Server: nginx/1.18.0 (Ubuntu) Date: Thu, 28 Nov 2024 02:44:40 GMT Content-Type: text/html; charset=utf-8 Transfer-Encoding: chunked Connection: close Set-Cookie: MoodleSession=aejqj47tn65rmnuqthin6bqg13; path=/; secure; HttpOnly Content-Language: en Content-Script-Type: text/javascript Content-Style-Type: text/css X-UA-Compatible: IE=edge Cache-Control: no-store, no-cache, must-revalidate Cache-Control: post-check=0, pre-check=0, no-transform Pragma: no-cache Expires: Mon, 20 Aug 1969 09:23:00 GMT Last-Modified: Thu, 28 Nov 2024 02:44:40 GMT Accept-Ranges: none X-Frame-Options: sameorigin Strict-Transport-Security: max-age=31536000; includeSubDomains X-Content-Type-Options: nosniff Referrer-Policy: origin Permissions-Policy: accelerometer=(), geolocation=(), gyroscope=(), magnetometer=(), payment=(), usb=()