nginx
tcp/443 tcp/80
GraphQL introspection is enabled.
This could leak to data leak if not properly configured.
Severity: medium
Fingerprint: c2db3a1c40d490db1a0bbaa3e31801bd40472f5f4692a336352437854411a405
GraphQL introspection enabled at /graphql Types: 128 (by kind: ENUM: 14, INPUT_OBJECT: 11, INTERFACE: 8, OBJECT: 90, SCALAR: 5) Operations: - Query: Query | fields: category, cmsBlocks, cmsPage, countries, country - Mutation: Mutation | fields: changeCustomerPassword, createCustomer, createCustomerAddress, createEmptyCart, deleteCustomerAddress Directives: deprecated, include, skip (total: 3)
Severity: medium
Fingerprint: c2db3a1c40d490db1a0bbaa3e31801bd40472f5f4692a33635243785e82edbf8
GraphQL introspection enabled at /graphql Types: 128 (by kind: ENUM: 14, INPUT_OBJECT: 11, INTERFACE: 8, OBJECT: 90, SCALAR: 5) Operations: - Query: Query | fields: category, cmsBlocks, cmsPage, countries, country - Mutation: Mutation | fields: changeCustomerPassword, createCustomer, createCustomerAddress, createEmptyCart, deleteCustomerAddress Directives: deprecated, include, skip (total: 3) Detected: Magento
GraphQL introspection is enabled.
This could leak to data leak if not properly configured.
Severity: medium
Fingerprint: c2db3a1c40d490db1a0bbaa3e31801bd40472f5f4692a336352437854411a405
GraphQL introspection enabled at /graphql Types: 128 (by kind: ENUM: 14, INPUT_OBJECT: 11, INTERFACE: 8, OBJECT: 90, SCALAR: 5) Operations: - Query: Query | fields: category, cmsBlocks, cmsPage, countries, country - Mutation: Mutation | fields: changeCustomerPassword, createCustomer, createCustomerAddress, createEmptyCart, deleteCustomerAddress Directives: deprecated, include, skip (total: 3)
Severity: medium
Fingerprint: c2db3a1c40d490db1a0bbaa3e31801bd40472f5f4692a33635243785e82edbf8
GraphQL introspection enabled at /graphql Types: 128 (by kind: ENUM: 14, INPUT_OBJECT: 11, INTERFACE: 8, OBJECT: 90, SCALAR: 5) Operations: - Query: Query | fields: category, cmsBlocks, cmsPage, countries, country - Mutation: Mutation | fields: changeCustomerPassword, createCustomer, createCustomerAddress, createEmptyCart, deleteCustomerAddress Directives: deprecated, include, skip (total: 3) Detected: Magento
Open service 85.90.244.215:80 · calliope.cosmobile.com
2026-01-26 00:07
HTTP/1.1 302 Found Server: nginx Date: Mon, 26 Jan 2026 00:07:16 GMT Content-Type: text/html; charset=UTF-8 Transfer-Encoding: chunked Connection: close Set-Cookie: PHPSESSID=3a5fa5158c08264df9654b8742cd3859; expires=Mon, 26-Jan-2026 01:07:16 GMT; Max-Age=3600; path=/; domain=calliope.cosmobile.com; HttpOnly Location: https://calliope.cosmobile.com/en/ Pragma: no-cache Cache-Control: max-age=0, must-revalidate, no-cache, no-store Expires: Sun, 26 Jan 2025 00:07:16 GMT X-Content-Type-Options: nosniff X-XSS-Protection: 1; mode=block X-Frame-Options: SAMEORIGIN Strict-Transport-Security: max-age=15768000
Open service 85.90.244.215:443 · calliope.cosmobile.com
2026-01-26 00:07
HTTP/1.1 200 OK Server: nginx Date: Mon, 26 Jan 2026 00:07:17 GMT Content-Type: text/html; charset=UTF-8 Transfer-Encoding: chunked Connection: close Vary: Accept-Encoding Set-Cookie: PHPSESSID=0f9efdcc1bbf419e3d3e790ef909fb31; expires=Mon, 26-Jan-2026 01:07:16 GMT; Max-Age=3600; path=/; domain=calliope.cosmobile.com; secure; HttpOnly Pragma: no-cache Cache-Control: max-age=0, must-revalidate, no-cache, no-store Expires: Sun, 26 Jan 2025 00:07:16 GMT X-Content-Type-Options: nosniff X-XSS-Protection: 1; mode=block X-Frame-Options: SAMEORIGIN Strict-Transport-Security: max-age=15768000
Open service 85.90.244.215:443 · calliope.cosmobile.com
2026-01-23 13:01
HTTP/1.1 200 OK Server: nginx Date: Fri, 23 Jan 2026 13:01:31 GMT Content-Type: text/html; charset=UTF-8 Transfer-Encoding: chunked Connection: close Vary: Accept-Encoding Set-Cookie: PHPSESSID=2bc7be49d34df7ee91c95b6a371e7d7c; expires=Fri, 23-Jan-2026 14:01:31 GMT; Max-Age=3600; path=/; domain=calliope.cosmobile.com; secure; HttpOnly Pragma: no-cache Cache-Control: max-age=0, must-revalidate, no-cache, no-store Expires: Thu, 23 Jan 2025 13:01:31 GMT X-Content-Type-Options: nosniff X-XSS-Protection: 1; mode=block X-Frame-Options: SAMEORIGIN Strict-Transport-Security: max-age=15768000
Open service 85.90.244.215:80 · calliope.cosmobile.com
2026-01-23 12:06
HTTP/1.1 302 Found Server: nginx Date: Fri, 23 Jan 2026 12:06:37 GMT Content-Type: text/html; charset=UTF-8 Transfer-Encoding: chunked Connection: close Set-Cookie: PHPSESSID=b4c2a172f6bd32bedbb36ef26c8a4e45; expires=Fri, 23-Jan-2026 13:06:37 GMT; Max-Age=3600; path=/; domain=calliope.cosmobile.com; HttpOnly Location: https://calliope.cosmobile.com/en/ Pragma: no-cache Cache-Control: max-age=0, must-revalidate, no-cache, no-store Expires: Thu, 23 Jan 2025 12:06:37 GMT X-Content-Type-Options: nosniff X-XSS-Protection: 1; mode=block X-Frame-Options: SAMEORIGIN Strict-Transport-Security: max-age=15768000
Open service 85.90.244.215:443 · calliope.cosmobile.com
2026-01-10 01:38
HTTP/1.1 200 OK Server: nginx Date: Sat, 10 Jan 2026 01:38:36 GMT Content-Type: text/html; charset=UTF-8 Transfer-Encoding: chunked Connection: close Vary: Accept-Encoding Set-Cookie: PHPSESSID=0ea34f73ba875b97bbff81f10017c260; expires=Sat, 10-Jan-2026 02:38:36 GMT; Max-Age=3600; path=/; domain=calliope.cosmobile.com; secure; HttpOnly Pragma: no-cache Cache-Control: max-age=0, must-revalidate, no-cache, no-store Expires: Fri, 10 Jan 2025 01:38:36 GMT X-Content-Type-Options: nosniff X-XSS-Protection: 1; mode=block X-Frame-Options: SAMEORIGIN Strict-Transport-Security: max-age=15768000