Apache
tcp/443
GraphQL introspection is enabled.
This could leak to data leak if not properly configured.
Severity: medium
Fingerprint: c2db3a1c40d490db1a0bbaa37dd2db492eb743ebbd7f0c0cdef2a19a5e28dcda
GraphQL introspection enabled at /graphql Types: 55 (by kind: ENUM: 10, INPUT_OBJECT: 6, OBJECT: 33, SCALAR: 6) Operations: - Query: Query | fields: me, product, products, shopInfo, shoppingCart - Mutation: Mutation | fields: addToCart, loginWeb, removeFromCart, removeFromWaitlist, updateCartQuantity Directives: deprecated, include, skip (total: 3)
Open service 151.101.130.132:443 · freckledcharm.com
2026-01-08 23:47
HTTP/1.1 200 OK Connection: close Content-Type: text/html; charset=UTF-8 Server: Apache Cache-Control: no-cache, private Content-Security-Policy-Report-Only: default-src 'self'; script-src * 'unsafe-inline' 'unsafe-eval'; style-src * 'unsafe-inline'; img-src * data: blob: android-webview-video-poster:; font-src * data:; connect-src * blob:; media-src * blob:; frame-src * blob: navigate:; worker-src 'self' blob:; frame-ancestors *; form-action 'self' www.facebook.com tr.snapchat.com pos.commentsold.com; object-src 'none'; manifest-src *; child-src 'self' blob:; report-uri https://o43862.ingest.sentry.io/api/239693/security/?sentry_key=deb2fc6b7d104f7ea6241356c26c14d0 x-robots-tag: all X-Request-Id: 043b80f9-bbc6-47ea-8f08-e11a922a2bcf Set-Cookie: laravel_session=eyJpdiI6IkxKZVduOFhOZHF4eHFvMTBETkgzenc9PSIsInZhbHVlIjoiRXV5L0lEdDdtQ1BGZklNbGh2RjR2Wkt6WC9iQWFhYUNVa3B1TGhhMXp4N1g3UTRCUERXQ1FmMCt5WTZYRHpCaXV1M3NSU0wvdENYTGFkS3BzK3kzcW5vWlNPZnhIcFdNQzRkUVEvZTVpY3lKb0FVZTNEUjhKSDgzNGpiRDE0NEkiLCJtYWMiOiJiZWZhODQ0ZWNjM2RiZjc3MjNiYWJmMDM4OGU5YzNiYTYwNDI5OTdlM2YzOWRjMDcxNWVhYmI5MGEwZTRkNTA0IiwidGFnIjoiIn0%3D; expires=Mon, 09 Mar 2026 23:47:53 GMT; Max-Age=5184000; path=/; secure; httponly; samesite=none Set-Cookie: ntXmMaA356OBP9os211s1XkVSZsaYuLxGdiiD1iz=eyJpdiI6ImJGQkk0eHE2Y3RBY29NODlsRzVRZEE9PSIsInZhbHVlIjoic2dGNWx0QzNHUEZ4dHhwbDlubDJrYVpEWjdtQldSQ1JINVlwY0xDRUFsNEk2SElhRkJrYlBhMUNEclU3ZnR2VzFkZ0ZjTXVLbE1yNmdPVXdkSXA4QWhRekVrbDNRRUtHSVpwVHlDUWxuYXN1b29ZMFA1dmZBZHVNTzV5YUpzSTBIaVl6Mk5RUmVrNUFsUnhUYTJpcEVTTHR3dG5mK0ZsOGF5SW45L1M5SHQ0aHgvd1lCWTJpamlRZ1JZZlYxUzRtSmZ5QWVZWnJQRVA3VGg4WTBoWlRWbklwSlVxSjR5b1cwZTEraDdqVzVqZllra0N2Sk5uTk5DT29JanhRclN0dFI5Q0lJcWI1VCtIdzZVQWRxcmpBUE5PcmIwTzdLT3BIUGtlUWtnbkdGdkorWFpnZG80c0thcWduazIrU2UwZ2o4ZFpLbU1JWjRHOVlQdXJnYXV1QXVpVkIzOFJTZXkzMW1xdTFsbzF1ejNDQzd6aStBRU5OeGphREdYMU05U3VqOWs2MVMyb1JLQmt5c0J6ZVJOMk1lcGZMMFl0OGhlOVhsMlBFaERUaDBOK3hiVzRWWmZ2ejhVMHJZenArS0hrN3FMVlYvSTA5Q3Y0ZDU4eHVxZUFXVHdlcHV6U2ZlZUZ6V3d0MEVsOC85SFhBUmp2VzJQMGlWR2oySWhtSGJXSy8iLCJtYWMiOiJhYWZiMWFmODdkMmNhNzNlODE3ZTdkOWM3MTVlMzE2ZmMxMGVkZjUwYTdkZmM0M2JjZDdlZDk0MzJiMGM2YzY2IiwidGFnIjoiIn0%3D; expires=Mon, 09 Mar 2026 23:47:53 GMT; Max-Age=5184000; path=/; secure; httponly; samesite=none Access-Control-Allow-Origin: * Access-Control-Allow-Methods: POST, GET, OPTIONS, DELETE, PUT Access-Control-Max-Age: 1000 Access-Control-Allow-Headers: x-requested-with, Content-Type, origin, authorization, accept, client-security-token, Accept-Encoding Accept-Ranges: bytes Via: 1.1 varnish, 1.1 varnish X-Cacheable: NO:Set-Cookie Date: Thu, 08 Jan 2026 23:47:53 GMT X-Served-By: cache-chi-kigq8000136-CHI, cache-lcy-egml8630074-LCY X-Cache: MISS, MISS X-Cache-Hits: 0, 0 X-Timer: S1767916073.417928,VS0,VE250 Vary: Accept-Encoding Strict-Transport-Security: max-age=900 transfer-encoding: chunked
Open service 151.101.130.132:443 · freckledcharm.com
2026-01-02 01:57
HTTP/1.1 200 OK Connection: close Content-Type: text/html; charset=UTF-8 Server: Apache Cache-Control: no-cache, private Content-Security-Policy-Report-Only: default-src 'self'; script-src * 'unsafe-inline' 'unsafe-eval'; style-src * 'unsafe-inline'; img-src * data: blob: android-webview-video-poster:; font-src * data:; connect-src * blob:; media-src * blob:; frame-src * blob: navigate:; worker-src 'self' blob:; frame-ancestors *; form-action 'self' www.facebook.com tr.snapchat.com pos.commentsold.com; object-src 'none'; manifest-src *; child-src 'self' blob:; report-uri https://o43862.ingest.sentry.io/api/239693/security/?sentry_key=deb2fc6b7d104f7ea6241356c26c14d0 x-robots-tag: all X-Request-Id: 77e0dc29-e302-4f43-be67-3633a1cdf7a6 Set-Cookie: laravel_session=eyJpdiI6IngwRVZpMTlkYjZSRkJWMjJjT3VKMVE9PSIsInZhbHVlIjoianRIZFlVNHFYcDFPYVducS9LN3l6UVIrQXlSUUh5QU9wc1ZoRUQ4Y2M2Umx2eFNUK3drUWhKQVE5MGk3TjJieUJma3VxcXpOM1pzc3JvOCtPM3hwVEwxcnFoUDFyNDRHcVZWR21JTTl0TWZBM0htQnJRL1VJcVdIUFNveHR6aVMiLCJtYWMiOiJhMTJlMjQ1NDQ4OGFjNjI0MTU3NmZlMTdlY2Y5NmNhOTk0Zjg4ODA0YTUzOWI5NDgyYzYwMWE3NzhhZGE3ZTk5IiwidGFnIjoiIn0%3D; expires=Tue, 03 Mar 2026 01:57:07 GMT; Max-Age=5184000; path=/; secure; httponly; samesite=none Set-Cookie: IoNQjM3wm8b4uebI274gCKbzrpNOoyFrW3o5163c=eyJpdiI6IkdZVlZmSEpYZEEvS2x4ZExyT3d5OFE9PSIsInZhbHVlIjoiNk9wWUtCeTU3WEh2OW85c1REd0kza3R1dEJIcDdkdTg3TXhMNXBydzBZSndJZjlLNmZVNWI3WTNGV2lxZFN3bzRuRWJMb3J0M1RyYXhPeXllQUkvbVFJSm9vSzZBbGtKSTlQdU92eDNIa0d0cm5JWFlGdHhra1RXUFRqbUEyQzdRYVpWSlFOa3dDTmh3a3VTdm91UzZiZzdSQTZNZHVLZnUzdlBVR2ZHS2dIMlE4eFBaL1F2QkYrS0QxQXFpaUpuMHQ2R25nZURtb3dTOFA5bm9aWXppOS9hQ3hpUVFBZ01EdWYzaEI1WkcydUpocndWZUFZekFpV3l2bnhTQ2ZyM0lFMjB3VzV3aXlEeFR0VHZ5a0hPTElydkVTYVp0eGFyY1hTSUpRQlU5dzIvRm9ZZXl2eGViWEN3bHlVZnUvalpwOUV1dGlXUDVXaXdFQ2V3T1JwZEIwaDJBeEV2QWFCK25vTUJJZXR0b3BvaTBzQ0RRdGk0WVZKemZKREh6TE1wZ3ZsT1JmL2NRMUxDVjlvaThZVHRZNThlSVpNSzFvUXBPRzJZcVpzT2EzUlU0cmp1anZDeUxwOHNteXpXb01aNDRocGxBdklGcDhhS0xZeVJaTG5OSVFSalJLLytpTmZuQlZjdCtkTDlHN2VZakU4MXZ4M1grUWNaSnRrUnRnZy8iLCJtYWMiOiIyNzlmZWNmNjI4NGVkMGQ3OGU3Njk4NTU4ZTVlMjY1YTI4NmNkYjkwYzVhYTJlY2I1OTk2Mzg0MTRhZWVmOWNlIiwidGFnIjoiIn0%3D; expires=Tue, 03 Mar 2026 01:57:07 GMT; Max-Age=5184000; path=/; secure; httponly; samesite=none Access-Control-Allow-Origin: * Access-Control-Allow-Methods: POST, GET, OPTIONS, DELETE, PUT Access-Control-Max-Age: 1000 Access-Control-Allow-Headers: x-requested-with, Content-Type, origin, authorization, accept, client-security-token, Accept-Encoding Accept-Ranges: bytes Via: 1.1 varnish, 1.1 varnish X-Cacheable: NO:Set-Cookie Date: Fri, 02 Jan 2026 01:57:07 GMT X-Served-By: cache-chi-kigq8000118-CHI, cache-pao-kpao1770040-PAO X-Cache: MISS, MISS X-Cache-Hits: 0, 0 X-Timer: S1767319027.003553,VS0,VE270 Vary: Accept-Encoding Strict-Transport-Security: max-age=900 transfer-encoding: chunked
Open service 151.101.130.132:443 · freckledcharm.com
2025-12-22 19:19
HTTP/1.1 200 OK Connection: close Content-Type: text/html; charset=UTF-8 Server: Apache Cache-Control: no-cache, private Content-Security-Policy-Report-Only: default-src 'self'; script-src * 'unsafe-inline' 'unsafe-eval'; style-src * 'unsafe-inline'; img-src * data: blob: android-webview-video-poster:; font-src * data:; connect-src * blob:; media-src * blob:; frame-src * blob: navigate:; worker-src 'self' blob:; frame-ancestors *; form-action 'self' www.facebook.com tr.snapchat.com pos.commentsold.com; object-src 'none'; manifest-src *; child-src 'self' blob:; report-uri https://o43862.ingest.sentry.io/api/239693/security/?sentry_key=deb2fc6b7d104f7ea6241356c26c14d0 x-robots-tag: all X-Request-Id: f2c3ab54-f70e-457c-8751-f4a9da87b2d8 Set-Cookie: laravel_session=eyJpdiI6Ik5LemFOV1E2R01kQ1hvQzRtelY1Ync9PSIsInZhbHVlIjoiZ1B0ZFlXUHAxeDZOcitRSGFkb1hIalZLN2JkWnE0bEJLcmVDbFZuVFY3ZzZMVEp5SEJQYnFycENQWFliMVdORExBbDZXYUp2WjBHOXQ4Q0NaNm9CeG1NUTRDaVlIRWE1Ym5rQitGVC9WeXdON0syYjFkeG8valhqTnVZTkVIeUIiLCJtYWMiOiIwOGM3NjgxNTcxMDdlMzMxZjM3ZTEzNzU0YmViMTk2YWYyN2I5OTE3ZjBiZmRmZWE5YmNiOThhYTQ1NGViNzlmIiwidGFnIjoiIn0%3D; expires=Fri, 20 Feb 2026 19:19:45 GMT; Max-Age=5184000; path=/; secure; httponly; samesite=none Set-Cookie: iNjGIm5k0rMegwT2q1AMsxN6w9wfcvpNzwBkjtZC=eyJpdiI6InNxQTN0bzNiVDFmL3R6c2IwQXJSemc9PSIsInZhbHVlIjoiZTZXdW1HbnBYc3U2c2V2QWh1TWcxYmJLdVozYmlQc3F3RHNYNlVsY29BVHdmdXdzMEcxb0xnQng1T3EySmQyWWlnTzJDQk5NQzJLUzl5YVhlL3NYZ3JpOU9UMGs0dnFRVjQ1YWtIS0YyNVQ5NnhQYzduM3ZNVVJnMHBsVWh5ZHp1Nm9xZGNpY0Z4MVNqRnE0QU5hREw4anJJcEhmWktva1dmTmozeUc3VHZjbGdtbnhRZVBIWlVEb0p2RkphL0UvS3IrM3piQ0hlcmlyNHhJbTF3WFpLT0VGVnlwTmYwV3haQkFGamFKaXVQcjVKd1dSSThwM3VwbU5JRVdqdnRldWVkQkF2d0xqcVV2bWsvMUx0UDdWV3U1a043NXo4ckJseEMrSTBhVGxXTHFiQWFsdUFtNVlPT3JnUElFa0VpRVVmU0JGT1MzOTJkK1JUSmNmM005SHRBTCtaUzA4QmltbkpCWlFWYXVMQlIvQkwrdHZ5VVBPaWxRanpjSTBBL3N5OU1TRWV6Wi9YMng2UHpXaDgySXI0L0Y4N3NUTEk5OVo0UElrN3hOSncrYUZMMlNrOWhrdnkvYjhsRmZSa2o3dWxYUHpEQ0xNL3k2RmxuYkpXeFlpZjFZWDB1U1UvWHU1UWNHeU1icTUxL3pJcm4xU3VObjVpdzIySXJWNzI4dU4iLCJtYWMiOiIzODNhYzE3ZDA5NzlhMGVmYmRiZDEwZjE3MmIyMjFiMzRlNzU3YzU1YTg5ZWE5Njk3ZjA2ZWIxYTcwZWRhYjBmIiwidGFnIjoiIn0%3D; expires=Fri, 20 Feb 2026 19:19:45 GMT; Max-Age=5184000; path=/; secure; httponly; samesite=none Access-Control-Allow-Origin: * Access-Control-Allow-Methods: POST, GET, OPTIONS, DELETE, PUT Access-Control-Max-Age: 1000 Access-Control-Allow-Headers: x-requested-with, Content-Type, origin, authorization, accept, client-security-token, Accept-Encoding Accept-Ranges: bytes Via: 1.1 varnish, 1.1 varnish X-Cacheable: NO:Set-Cookie Date: Mon, 22 Dec 2025 19:19:45 GMT X-Served-By: cache-chi-kigq8000108-CHI, cache-yyz4555-YYZ X-Cache: MISS, MISS X-Cache-Hits: 0, 0 X-Timer: S1766431186.591483,VS0,VE218 Vary: Accept-Encoding Strict-Transport-Security: max-age=900 transfer-encoding: chunked
Open service 151.101.130.132:443 · freckledcharm.com
2025-12-20 20:26
HTTP/1.1 200 OK Connection: close Content-Type: text/html; charset=UTF-8 Server: Apache Cache-Control: no-cache, private Content-Security-Policy-Report-Only: default-src 'self'; script-src * 'unsafe-inline' 'unsafe-eval'; style-src * 'unsafe-inline'; img-src * data: blob: android-webview-video-poster:; font-src * data:; connect-src * blob:; media-src * blob:; frame-src * blob: navigate:; worker-src 'self' blob:; frame-ancestors *; form-action 'self' www.facebook.com tr.snapchat.com pos.commentsold.com; object-src 'none'; manifest-src *; child-src 'self' blob:; report-uri https://o43862.ingest.sentry.io/api/239693/security/?sentry_key=deb2fc6b7d104f7ea6241356c26c14d0 x-robots-tag: all X-Request-Id: 2e37db81-4367-4859-8aa1-9dbd4ea78e98 Set-Cookie: laravel_session=eyJpdiI6ImlVems2aTlkTVRQOEhMdGhzN3Q3Umc9PSIsInZhbHVlIjoiU2xKVTJUNGdGTDhlc2lrRFhIclJ5TGNKM2dsa1Y4aTBPWGdXNEtlSTVFMmlyL0JRWUozbGxjSHh6bFZzeXYxRGZUSTRuekk2T3ZQRHlLQTRiR1JjYVhwc3pYYzhiN1BDMEZBOTNEUUJhR1hSRFUyNlZyMm9PaGNkSlpncUpXOXMiLCJtYWMiOiI5OTZmNjYwMDUzNmFkZTZkOTMwYjg1ZWI4ZmYzZDQxOGQ5NWUzYTZjOGZlY2JiZmJiNzg3NDgwNDQ3OGM3NGMzIiwidGFnIjoiIn0%3D; expires=Wed, 18 Feb 2026 20:26:14 GMT; Max-Age=5184000; path=/; secure; httponly; samesite=none Set-Cookie: FvFdBOcNTaIbBY9fk6z1gh90rJfpoayo8T7jFbOa=eyJpdiI6Ik83RzBmREZCL2VLUjdTazZxa3pyM1E9PSIsInZhbHVlIjoiR1JkOUlFSlBKRmJFeTNtZXJlYlVWazFHb1p1cFhPdjhuZi9TdmhodFFGRDVjb0RsNUhWTGs1WENCVEtsWExkM25kelQ2OEZqZlZqa0cvd2pRVStRcHJBVHN0V2FzZWtkNEZUQmUya1dVK3RVRi81T0M4V1NpTFRRdXpCbmJFRzkzODdPWGoxWHdwVDd1d0NMcGs5aG00dkpmUk9XL2E4L2F5c3hERVMyZFRMYzVnNmcreGNCQ29sZE04dTRIMjh3a2paaWlFWGdHZU1TNVBVTW5QV2Q0b2ZBcXU3ZnFoc1dBTTcyM1p1YTM4S29HVTFUSk50bG1sbldlMjE2MktIWTBZZ1ozdWxDRTZBYkdpQ0QxYmQ5OXN6REI5bFp6cjNpZ0JPejFxL28zaC8xOS90UndFbUxNbDJYb1dNOHZWMkpvREt1a2dMZHhFampiWVdwbWVpZmhVOGZhb0hwL0lBMTFFQjNwazBFQXpTaVRYNVY2eXBnS1lvNTBLb3hGc0FWWVFoMXVMR2tQR2RRWFBTMU40UXpXL21SeUk0ejFtb2pHTitLNEd1NlhFM1lLYitxUmE1SWhWcktJaW9BbkJSdUFHaHBVVUh6M2xMLzdtcXVYU1RITHlRb2pTNmtINUpLSWU3c2lZeEZTcDRpSmV5akZGbklwSXRyLy9XVmxYTnIiLCJtYWMiOiI4YTdmNjk5ZDhjYzVmZThjN2JmZWIzYzc1YmMwYWE2NDQ3YzRmZTYwZWRjOGYxNzUwNTJhMjMzNzI2Y2MwOTc3IiwidGFnIjoiIn0%3D; expires=Wed, 18 Feb 2026 20:26:14 GMT; Max-Age=5184000; path=/; secure; httponly; samesite=none Access-Control-Allow-Origin: * Access-Control-Allow-Methods: POST, GET, OPTIONS, DELETE, PUT Access-Control-Max-Age: 1000 Access-Control-Allow-Headers: x-requested-with, Content-Type, origin, authorization, accept, client-security-token, Accept-Encoding Accept-Ranges: bytes Via: 1.1 varnish, 1.1 varnish X-Cacheable: NO:Set-Cookie Date: Sat, 20 Dec 2025 20:26:14 GMT X-Served-By: cache-chi-klot8100101-CHI, cache-sin-wsss1830044-SIN X-Cache: MISS, MISS X-Cache-Hits: 0, 0 X-Timer: S1766262374.475581,VS0,VE487 Vary: Accept-Encoding Strict-Transport-Security: max-age=900 transfer-encoding: chunked