Apache 2.4.56
tcp/443 tcp/80
The following URL (usually /.git/config
) is publicly accessible and is leaking source code and repository configuration.
Severity: medium
Fingerprint: 2580fa947178c88602b1737db148c044b81b03713d63bb82370a6522a80d22fa
[core] repositoryformatversion = 0 filemode = true bare = false logallrefupdates = true [remote "origin"] url = git://git.moodle.org/moodle.git fetch = +refs/heads/*:refs/remotes/origin/* [branch "master"] remote = origin merge = refs/heads/master [branch "MOODLE_401_STABLE"] remote = origin merge = refs/heads/MOODLE_401_STABLE [branch "MOODLE_39_STABLE"] remote = origin merge = refs/heads/MOODLE_39_STABLE [branch "MOODLE_400_STABLE"] remote = origin merge = refs/heads/MOODLE_400_STABLE
The following Moodle application is publicly accessible and looks out-dated :
It is highly recommended to update to a safe version as soon as possible since multiple CVEs allow remote attackers to craft XSS attacks leading to code execution on the server.
If the application was already patched, reloading the web server to clear the PHP opcache will fix issue.
Reference:
Severity: high
Fingerprint: 0b591a20d83e9bbda3370ce58008084480080844800808448008084480080844
Found vulnerable Moodle application: Affected by CVE-2023-30943
The following URL (usually /.git/config
) is publicly accessible and is leaking source code and repository configuration.
Severity: medium
Fingerprint: 2580fa947178c88602b1737db148c044b81b03713d63bb82370a6522a80d22fa
[core] repositoryformatversion = 0 filemode = true bare = false logallrefupdates = true [remote "origin"] url = git://git.moodle.org/moodle.git fetch = +refs/heads/*:refs/remotes/origin/* [branch "master"] remote = origin merge = refs/heads/master [branch "MOODLE_401_STABLE"] remote = origin merge = refs/heads/MOODLE_401_STABLE [branch "MOODLE_39_STABLE"] remote = origin merge = refs/heads/MOODLE_39_STABLE [branch "MOODLE_400_STABLE"] remote = origin merge = refs/heads/MOODLE_400_STABLE
Open service 45.130.12.233:443 · beyazcourses.e-mektep.com
2024-12-22 04:11
HTTP/1.1 200 OK Date: Sun, 22 Dec 2024 04:11:39 GMT Server: Apache/2.4.56 (Debian) Set-Cookie: MoodleSession=pffuhml0g11595k1grr674h9q8; path=/; secure Expires: Mon, 20 Aug 1969 09:23:00 GMT Cache-Control: no-store, no-cache, must-revalidate Pragma: no-cache Content-Language: tr Content-Script-Type: text/javascript Content-Style-Type: text/css X-UA-Compatible: IE=edge Cache-Control: post-check=0, pre-check=0, no-transform Last-Modified: Sun, 22 Dec 2024 04:11:39 GMT Accept-Ranges: none X-Frame-Options: sameorigin Vary: Accept-Encoding Connection: close Transfer-Encoding: chunked Content-Type: text/html; charset=utf-8
Open service 45.130.12.233:443 · beyazcourses.e-mektep.com
2024-12-20 05:45
HTTP/1.1 200 OK Date: Fri, 20 Dec 2024 05:45:06 GMT Server: Apache/2.4.56 (Debian) Set-Cookie: MoodleSession=54m7cdsdgik3av3kehb7p5r6c1; path=/; secure Expires: Mon, 20 Aug 1969 09:23:00 GMT Cache-Control: no-store, no-cache, must-revalidate Pragma: no-cache Content-Language: tr Content-Script-Type: text/javascript Content-Style-Type: text/css X-UA-Compatible: IE=edge Cache-Control: post-check=0, pre-check=0, no-transform Last-Modified: Fri, 20 Dec 2024 05:45:06 GMT Accept-Ranges: none X-Frame-Options: sameorigin Vary: Accept-Encoding Connection: close Transfer-Encoding: chunked Content-Type: text/html; charset=utf-8
Open service 45.130.12.233:443 · beyazcourses.e-mektep.com
2024-12-20 04:23
HTTP/1.1 200 OK Date: Fri, 20 Dec 2024 04:23:16 GMT Server: Apache/2.4.56 (Debian) Set-Cookie: MoodleSession=skefe2gcanq4aa9snt12ino3go; path=/; secure Expires: Mon, 20 Aug 1969 09:23:00 GMT Cache-Control: no-store, no-cache, must-revalidate Pragma: no-cache Content-Language: tr Content-Script-Type: text/javascript Content-Style-Type: text/css X-UA-Compatible: IE=edge Cache-Control: post-check=0, pre-check=0, no-transform Last-Modified: Fri, 20 Dec 2024 04:23:16 GMT Accept-Ranges: none X-Frame-Options: sameorigin Vary: Accept-Encoding Connection: close Transfer-Encoding: chunked Content-Type: text/html; charset=utf-8
Open service 45.130.12.233:443 · beyazcourses.e-mektep.com
2024-12-19 01:17
HTTP/1.1 200 OK Date: Thu, 19 Dec 2024 01:17:06 GMT Server: Apache/2.4.56 (Debian) Set-Cookie: MoodleSession=gd426u1s6tgbs60ccpo3cuhtg0; path=/; secure Expires: Mon, 20 Aug 1969 09:23:00 GMT Cache-Control: no-store, no-cache, must-revalidate Pragma: no-cache Content-Language: tr Content-Script-Type: text/javascript Content-Style-Type: text/css X-UA-Compatible: IE=edge Cache-Control: post-check=0, pre-check=0, no-transform Last-Modified: Thu, 19 Dec 2024 01:17:06 GMT Accept-Ranges: none X-Frame-Options: sameorigin Vary: Accept-Encoding Connection: close Transfer-Encoding: chunked Content-Type: text/html; charset=utf-8
Open service 45.130.12.233:443 · beyazcourses.e-mektep.com
2024-12-18 21:13
HTTP/1.1 200 OK Date: Wed, 18 Dec 2024 21:13:45 GMT Server: Apache/2.4.56 (Debian) Set-Cookie: MoodleSession=ul0a10q8e107h6jf70bko1im87; path=/; secure Expires: Mon, 20 Aug 1969 09:23:00 GMT Cache-Control: no-store, no-cache, must-revalidate Pragma: no-cache Content-Language: tr Content-Script-Type: text/javascript Content-Style-Type: text/css X-UA-Compatible: IE=edge Cache-Control: post-check=0, pre-check=0, no-transform Last-Modified: Wed, 18 Dec 2024 21:13:46 GMT Accept-Ranges: none X-Frame-Options: sameorigin Vary: Accept-Encoding Connection: close Transfer-Encoding: chunked Content-Type: text/html; charset=utf-8
Open service 45.130.12.233:443 · beyazcourses.e-mektep.com
2024-12-14 13:02
HTTP/1.1 200 OK Date: Sat, 14 Dec 2024 13:02:45 GMT Server: Apache/2.4.56 (Debian) Set-Cookie: MoodleSession=lkfd9m5frdhs2njq0b44vjvgmi; path=/; secure Expires: Mon, 20 Aug 1969 09:23:00 GMT Cache-Control: no-store, no-cache, must-revalidate Pragma: no-cache Content-Language: tr Content-Script-Type: text/javascript Content-Style-Type: text/css X-UA-Compatible: IE=edge Cache-Control: post-check=0, pre-check=0, no-transform Last-Modified: Sat, 14 Dec 2024 13:02:45 GMT Accept-Ranges: none X-Frame-Options: sameorigin Vary: Accept-Encoding Connection: close Transfer-Encoding: chunked Content-Type: text/html; charset=utf-8
Open service 45.130.12.233:443 · beyazcourses.e-mektep.com
2024-12-14 10:19
HTTP/1.1 200 OK Date: Sat, 14 Dec 2024 10:19:20 GMT Server: Apache/2.4.56 (Debian) Set-Cookie: MoodleSession=fqi58b8khbujeccav5cbitmlrm; path=/; secure Expires: Mon, 20 Aug 1969 09:23:00 GMT Cache-Control: no-store, no-cache, must-revalidate Pragma: no-cache Content-Language: tr Content-Script-Type: text/javascript Content-Style-Type: text/css X-UA-Compatible: IE=edge Cache-Control: post-check=0, pre-check=0, no-transform Last-Modified: Sat, 14 Dec 2024 10:19:20 GMT Accept-Ranges: none X-Frame-Options: sameorigin Vary: Accept-Encoding Connection: close Transfer-Encoding: chunked Content-Type: text/html; charset=utf-8
Open service 45.130.12.233:443 · beyazcourses.e-mektep.com
2024-12-12 23:39
HTTP/1.1 200 OK Date: Thu, 12 Dec 2024 23:39:36 GMT Server: Apache/2.4.56 (Debian) Set-Cookie: MoodleSession=9ndnlbug6og210o97eng6d1rum; path=/; secure Expires: Mon, 20 Aug 1969 09:23:00 GMT Cache-Control: no-store, no-cache, must-revalidate Pragma: no-cache Content-Language: tr Content-Script-Type: text/javascript Content-Style-Type: text/css X-UA-Compatible: IE=edge Cache-Control: post-check=0, pre-check=0, no-transform Last-Modified: Thu, 12 Dec 2024 23:39:36 GMT Accept-Ranges: none X-Frame-Options: sameorigin Vary: Accept-Encoding Connection: close Transfer-Encoding: chunked Content-Type: text/html; charset=utf-8
Open service 45.130.12.233:443 · beyazcourses.e-mektep.com
2024-12-12 16:01
HTTP/1.1 200 OK Date: Thu, 12 Dec 2024 16:01:44 GMT Server: Apache/2.4.56 (Debian) Set-Cookie: MoodleSession=rf50adn7i4jjdc1tf410i21s9s; path=/; secure Expires: Mon, 20 Aug 1969 09:23:00 GMT Cache-Control: no-store, no-cache, must-revalidate Pragma: no-cache Content-Language: tr Content-Script-Type: text/javascript Content-Style-Type: text/css X-UA-Compatible: IE=edge Cache-Control: post-check=0, pre-check=0, no-transform Last-Modified: Thu, 12 Dec 2024 16:01:44 GMT Accept-Ranges: none X-Frame-Options: sameorigin Vary: Accept-Encoding Connection: close Transfer-Encoding: chunked Content-Type: text/html; charset=utf-8
Open service 45.130.12.233:443 · beyazcourses.e-mektep.com
2024-12-03 06:04
HTTP/1.1 200 OK Date: Tue, 03 Dec 2024 06:04:43 GMT Server: Apache/2.4.56 (Debian) Set-Cookie: MoodleSession=v8guughh0ammk9eetg2aev82ef; path=/; secure Expires: Mon, 20 Aug 1969 09:23:00 GMT Cache-Control: no-store, no-cache, must-revalidate Pragma: no-cache Content-Language: tr Content-Script-Type: text/javascript Content-Style-Type: text/css X-UA-Compatible: IE=edge Cache-Control: post-check=0, pre-check=0, no-transform Last-Modified: Tue, 03 Dec 2024 06:04:43 GMT Accept-Ranges: none X-Frame-Options: sameorigin Vary: Accept-Encoding Connection: close Transfer-Encoding: chunked Content-Type: text/html; charset=utf-8
Open service 45.130.12.233:443 · beyazcourses.e-mektep.com
2024-12-03 02:08
HTTP/1.1 200 OK Date: Tue, 03 Dec 2024 02:08:31 GMT Server: Apache/2.4.56 (Debian) Set-Cookie: MoodleSession=pic46f6517e6gedvckp1r61mkn; path=/; secure Expires: Mon, 20 Aug 1969 09:23:00 GMT Cache-Control: no-store, no-cache, must-revalidate Pragma: no-cache Content-Language: tr Content-Script-Type: text/javascript Content-Style-Type: text/css X-UA-Compatible: IE=edge Cache-Control: post-check=0, pre-check=0, no-transform Last-Modified: Tue, 03 Dec 2024 02:08:31 GMT Accept-Ranges: none X-Frame-Options: sameorigin Vary: Accept-Encoding Connection: close Transfer-Encoding: chunked Content-Type: text/html; charset=utf-8
Open service 45.130.12.233:443 · beyazcourses.e-mektep.com
2024-12-01 01:59
HTTP/1.1 200 OK Date: Sun, 01 Dec 2024 01:59:56 GMT Server: Apache/2.4.56 (Debian) Set-Cookie: MoodleSession=b41abcueiiaticp37acgc0m84p; path=/; secure Expires: Mon, 20 Aug 1969 09:23:00 GMT Cache-Control: no-store, no-cache, must-revalidate Pragma: no-cache Content-Language: tr Content-Script-Type: text/javascript Content-Style-Type: text/css X-UA-Compatible: IE=edge Cache-Control: post-check=0, pre-check=0, no-transform Last-Modified: Sun, 01 Dec 2024 01:59:56 GMT Accept-Ranges: none X-Frame-Options: sameorigin Vary: Accept-Encoding Connection: close Transfer-Encoding: chunked Content-Type: text/html; charset=utf-8
Open service 45.130.12.233:443 · beyazcourses.e-mektep.com
2024-11-30 22:26
HTTP/1.1 200 OK Date: Sat, 30 Nov 2024 22:26:31 GMT Server: Apache/2.4.56 (Debian) Set-Cookie: MoodleSession=56cgsppqd5esi18rmi9p1f4fhe; path=/; secure Expires: Mon, 20 Aug 1969 09:23:00 GMT Cache-Control: no-store, no-cache, must-revalidate Pragma: no-cache Content-Language: tr Content-Script-Type: text/javascript Content-Style-Type: text/css X-UA-Compatible: IE=edge Cache-Control: post-check=0, pre-check=0, no-transform Last-Modified: Sat, 30 Nov 2024 22:26:31 GMT Accept-Ranges: none X-Frame-Options: sameorigin Vary: Accept-Encoding Connection: close Transfer-Encoding: chunked Content-Type: text/html; charset=utf-8
Open service 45.130.12.233:443 · beyazcourses.e-mektep.com
2024-11-29 17:47
HTTP/1.1 200 OK Date: Fri, 29 Nov 2024 17:47:51 GMT Server: Apache/2.4.56 (Debian) Set-Cookie: MoodleSession=0d6rb5ulgrtvde8bhpo3bl1jp8; path=/; secure Expires: Mon, 20 Aug 1969 09:23:00 GMT Cache-Control: no-store, no-cache, must-revalidate Pragma: no-cache Content-Language: tr Content-Script-Type: text/javascript Content-Style-Type: text/css X-UA-Compatible: IE=edge Cache-Control: post-check=0, pre-check=0, no-transform Last-Modified: Fri, 29 Nov 2024 17:47:51 GMT Accept-Ranges: none X-Frame-Options: sameorigin Vary: Accept-Encoding Connection: close Transfer-Encoding: chunked Content-Type: text/html; charset=utf-8
Open service 45.130.12.233:80 · beyazcourses.e-mektep.com
2024-11-29 17:47
HTTP/1.1 301 Moved Permanently Date: Fri, 29 Nov 2024 17:47:48 GMT Server: Apache/2.4.56 (Debian) Location: https://beyazcourses.e-mektep.com/ Content-Length: 333 Connection: close Content-Type: text/html; charset=iso-8859-1 Page title: 301 Moved Permanently <!DOCTYPE HTML PUBLIC "-//IETF//DTD HTML 2.0//EN"> <html><head> <title>301 Moved Permanently</title> </head><body> <h1>Moved Permanently</h1> <p>The document has moved <a href="https://beyazcourses.e-mektep.com/">here</a>.</p> <hr> <address>Apache/2.4.56 (Debian) Server at beyazcourses.e-mektep.com Port 80</address> </body></html>
Open service 45.130.12.233:443 · beyazcourses.e-mektep.com
2024-11-29 00:09
HTTP/1.1 200 OK Date: Fri, 29 Nov 2024 00:09:17 GMT Server: Apache/2.4.56 (Debian) Set-Cookie: MoodleSession=jla5rniag40ln0oirj5mnd3lot; path=/; secure Expires: Mon, 20 Aug 1969 09:23:00 GMT Cache-Control: no-store, no-cache, must-revalidate Pragma: no-cache Content-Language: tr Content-Script-Type: text/javascript Content-Style-Type: text/css X-UA-Compatible: IE=edge Cache-Control: post-check=0, pre-check=0, no-transform Last-Modified: Fri, 29 Nov 2024 00:09:17 GMT Accept-Ranges: none X-Frame-Options: sameorigin Vary: Accept-Encoding Connection: close Transfer-Encoding: chunked Content-Type: text/html; charset=utf-8
Open service 45.130.12.233:443 · beyazcourses.e-mektep.com
2024-11-28 16:42
HTTP/1.1 200 OK Date: Thu, 28 Nov 2024 16:42:15 GMT Server: Apache/2.4.56 (Debian) Set-Cookie: MoodleSession=uipitpg75nc2fsdt83d8vf7bm0; path=/; secure Expires: Mon, 20 Aug 1969 09:23:00 GMT Cache-Control: no-store, no-cache, must-revalidate Pragma: no-cache Content-Language: tr Content-Script-Type: text/javascript Content-Style-Type: text/css X-UA-Compatible: IE=edge Cache-Control: post-check=0, pre-check=0, no-transform Last-Modified: Thu, 28 Nov 2024 16:42:15 GMT Accept-Ranges: none X-Frame-Options: sameorigin Vary: Accept-Encoding Connection: close Transfer-Encoding: chunked Content-Type: text/html; charset=utf-8
Open service 45.130.12.233:443 · beyazcourses.e-mektep.com
2024-11-26 21:25
HTTP/1.1 200 OK Date: Tue, 26 Nov 2024 21:25:33 GMT Server: Apache/2.4.56 (Debian) Set-Cookie: MoodleSession=omsctsbn6b7qndi524n8hqis1l; path=/; secure Expires: Mon, 20 Aug 1969 09:23:00 GMT Cache-Control: no-store, no-cache, must-revalidate Pragma: no-cache Content-Language: tr Content-Script-Type: text/javascript Content-Style-Type: text/css X-UA-Compatible: IE=edge Cache-Control: post-check=0, pre-check=0, no-transform Last-Modified: Tue, 26 Nov 2024 21:25:33 GMT Accept-Ranges: none X-Frame-Options: sameorigin Vary: Accept-Encoding Connection: close Transfer-Encoding: chunked Content-Type: text/html; charset=utf-8
Open service 45.130.12.233:443 · beyazcourses.e-mektep.com
2024-11-26 16:20
HTTP/1.1 200 OK Date: Tue, 26 Nov 2024 16:20:34 GMT Server: Apache/2.4.56 (Debian) Set-Cookie: MoodleSession=rbtqvmc771bn3irtepimi0flcm; path=/; secure Expires: Mon, 20 Aug 1969 09:23:00 GMT Cache-Control: no-store, no-cache, must-revalidate Pragma: no-cache Content-Language: tr Content-Script-Type: text/javascript Content-Style-Type: text/css X-UA-Compatible: IE=edge Cache-Control: post-check=0, pre-check=0, no-transform Last-Modified: Tue, 26 Nov 2024 16:20:34 GMT Accept-Ranges: none X-Frame-Options: sameorigin Vary: Accept-Encoding Connection: close Transfer-Encoding: chunked Content-Type: text/html; charset=utf-8
Open service 45.130.12.233:443 · beyazcourses.e-mektep.com
2024-11-20 18:35
HTTP/1.1 200 OK Date: Wed, 20 Nov 2024 18:35:23 GMT Server: Apache/2.4.56 (Debian) Set-Cookie: MoodleSession=8gj9hofafnd290coar2hcm0d7m; path=/; secure Expires: Mon, 20 Aug 1969 09:23:00 GMT Cache-Control: no-store, no-cache, must-revalidate Pragma: no-cache Content-Language: tr Content-Script-Type: text/javascript Content-Style-Type: text/css X-UA-Compatible: IE=edge Cache-Control: post-check=0, pre-check=0, no-transform Last-Modified: Wed, 20 Nov 2024 18:35:23 GMT Accept-Ranges: none X-Frame-Options: sameorigin Vary: Accept-Encoding Connection: close Transfer-Encoding: chunked Content-Type: text/html; charset=utf-8
Open service 45.130.12.233:443 · beyazcourses.e-mektep.com
2024-11-20 16:23
HTTP/1.1 200 OK Date: Wed, 20 Nov 2024 16:23:21 GMT Server: Apache/2.4.56 (Debian) Set-Cookie: MoodleSession=73rk5j1avn58eagg7fpr54b68a; path=/; secure Expires: Mon, 20 Aug 1969 09:23:00 GMT Cache-Control: no-store, no-cache, must-revalidate Pragma: no-cache Content-Language: tr Content-Script-Type: text/javascript Content-Style-Type: text/css X-UA-Compatible: IE=edge Cache-Control: post-check=0, pre-check=0, no-transform Last-Modified: Wed, 20 Nov 2024 16:23:21 GMT Accept-Ranges: none X-Frame-Options: sameorigin Vary: Accept-Encoding Connection: close Transfer-Encoding: chunked Content-Type: text/html; charset=utf-8