nginx
tcp/443
The following URL (usually /.git/config) is publicly accessible and is leaking source code and repository configuration.
Severity: high
Fingerprint: 2580fa947178c88602b1737db148c044b81b03713d63bb82370a65222f279983
[core] repositoryformatversion = 0 filemode = true bare = false logallrefupdates = true ignorecase = true precomposeunicode = true [remote "origin"] url = ssh://piotrmika_parafia@parafia.x25.pl/ fetch = +refs/heads/*:refs/remotes/origin/* [branch "master"] remote = origin merge = refs/heads/master
The following URL (usually /.git/config) is publicly accessible and is leaking source code and repository configuration.
Severity: high
Fingerprint: 2580fa947178c88602b1737db148c044b81b03713d63bb82370a65222f279983
[core] repositoryformatversion = 0 filemode = true bare = false logallrefupdates = true ignorecase = true precomposeunicode = true [remote "origin"] url = ssh://piotrmika_parafia@parafia.x25.pl/ fetch = +refs/heads/*:refs/remotes/origin/* [branch "master"] remote = origin merge = refs/heads/master
The following URL (usually /.git/config) is publicly accessible and is leaking source code and repository configuration.
Severity: high
Fingerprint: 2580fa947178c88602b1737db148c044b81b03713d63bb82370a65222f279983
[core] repositoryformatversion = 0 filemode = true bare = false logallrefupdates = true ignorecase = true precomposeunicode = true [remote "origin"] url = ssh://piotrmika_parafia@parafia.x25.pl/ fetch = +refs/heads/*:refs/remotes/origin/* [branch "master"] remote = origin merge = refs/heads/master
The following URL (usually /.git/config) is publicly accessible and is leaking source code and repository configuration.
Severity: high
Fingerprint: 2580fa947178c88602b1737db148c044b81b03713d63bb82370a65222f279983
[core] repositoryformatversion = 0 filemode = true bare = false logallrefupdates = true ignorecase = true precomposeunicode = true [remote "origin"] url = ssh://piotrmika_parafia@parafia.x25.pl/ fetch = +refs/heads/*:refs/remotes/origin/* [branch "master"] remote = origin merge = refs/heads/master
The following URL (usually /.git/config) is publicly accessible and is leaking source code and repository configuration.
Severity: high
Fingerprint: 2580fa947178c88602b1737db148c044b81b03713d63bb82370a65222f279983
[core] repositoryformatversion = 0 filemode = true bare = false logallrefupdates = true ignorecase = true precomposeunicode = true [remote "origin"] url = ssh://piotrmika_parafia@parafia.x25.pl/ fetch = +refs/heads/*:refs/remotes/origin/* [branch "master"] remote = origin merge = refs/heads/master
Open service 185.36.171.219:443 ยท pma.kwpos.pl
2026-01-10 01:38
HTTP/1.1 200 OK
Server: nginx
Date: Sat, 10 Jan 2026 01:38:13 GMT
Content-Type: text/html; charset=utf-8
Transfer-Encoding: chunked
Connection: close
Vary: Accept-Encoding
Set-Cookie: pma_lang_https=en; expires=Mon, 09-Feb-2026 01:38:13 GMT; Max-Age=2592000; path=/; secure; HttpOnly; SameSite=Strict
Set-Cookie: phpMyAdmin_https=19ergi9ece7qj54g18fsnp6f62; path=/; secure; HttpOnly
X-ob_mode: 1
X-Frame-Options: DENY
Referrer-Policy: no-referrer
Content-Security-Policy: default-src 'self' ;script-src 'self' 'unsafe-inline' 'unsafe-eval' ;style-src 'self' 'unsafe-inline' ;img-src 'self' data: *.tile.openstreetmap.org;object-src 'none';
X-Content-Security-Policy: default-src 'self' ;options inline-script eval-script;referrer no-referrer;img-src 'self' data: *.tile.openstreetmap.org;object-src 'none';
X-WebKit-CSP: default-src 'self' ;script-src 'self' 'unsafe-inline' 'unsafe-eval';referrer no-referrer;style-src 'self' 'unsafe-inline' ;img-src 'self' data: *.tile.openstreetmap.org;object-src 'none';
X-XSS-Protection: 1; mode=block
X-Content-Type-Options: nosniff
X-Permitted-Cross-Domain-Policies: none
X-Robots-Tag: noindex, nofollow
Expires: Sat, 10 Jan 2026 01:38:13 +0000
Cache-Control: no-store, no-cache, must-revalidate, pre-check=0, post-check=0, max-age=0
Pragma: no-cache
Last-Modified: Sat, 10 Jan 2026 01:38:13 +0000
Vary: Accept-Encoding
Page title: phpMyAdmin
<!doctype html>
<html lang="en" dir="ltr">
<head>
<meta charset="utf-8">
<meta name="viewport" content="width=device-width, initial-scale=1, shrink-to-fit=no">
<meta name="referrer" content="no-referrer">
<meta name="robots" content="noindex,nofollow">
<meta http-equiv="X-UA-Compatible" content="IE=Edge">
<style id="cfs-style">html{display: none;}</style>
<link rel="icon" href="favicon.ico" type="image/x-icon">
<link rel="shortcut icon" href="favicon.ico" type="image/x-icon">
<link rel="stylesheet" type="text/css" href="./themes/pmahomme/jquery/jquery-ui.css">
<link rel="stylesheet" type="text/css" href="js/vendor/codemirror/lib/codemirror.css?v=5.1.1">
<link rel="stylesheet" type="text/css" href="js/vendor/codemirror/addon/hint/show-hint.css?v=5.1.1">
<link rel="stylesheet" type="text/css" href="js/vendor/codemirror/addon/lint/lint.css?v=5.1.1">
<link rel="stylesheet" type="text/css" href="./themes/pmahomme/css/theme.css?v=5.1.1&nocache=2150149594ltr&server=1">
<link rel="stylesheet" type="text/css" href="./themes/pmahomme/css/printview.css?v=5.1.1" media="print" id="printcss">
<title>phpMyAdmin</title>
<script data-cfasync="false" type="text/javascript" src="js/vendor/jquery/jquery.min.js?v=5.1.1"></script>
<script data-cfasync="false" type="text/javascript" src="js/vendor/jquery/jquery-migrate.js?v=5.1.1"></script>
<script data-cfasync="false" type="text/javascript" src="js/vendor/sprintf.js?v=5.1.1"></script>
<script data-cfasync="false" type="text/javascript" src="js/dist/ajax.js?v=5.1.1"></script>
<script data-cfasync="false" type="text/javascript" src="js/dist/keyhandler.js?v=5.1.1"></script>
<script data-cfasync="false" type="text/javascript" src="js/vendor/bootstrap/bootstrap.bundle.min.js?v=5.1.1"></script>
<script data-cfasync="false" type="text/javascript" src="js/vendor/jquery/jquery-ui.min.js?v=5.1.1"></script>
<script data-cfasync="false" type="text/javascript" src="js/vendor/js.cookie.js?v=5.1.1"></script>
<script data-cfasync="false" type="text/javascript" src="js/vendor/jquery/jquery.mousewheel.js?v=5.1.1"></script>
<script data-cfasync="false" type="text/javascript" src="js/vendor/jquery/jquery.validate.js?v=5.1.1"></script>
<script data-cfasync="false" type="text/javascript" src="js/vendor/jquery/jquery-ui-timepicker-addon.js?v=5.1.1"></script>
<script data-cfasync="false" type="text/javascript" src="js/vendor/jquery/jquery.ba-hashchange-2.0.js?v=5.1.1"></script>
<script data-cfasync="false" type="text/javascript" src="js/vendor/jquery/jquery.debounce-1.0.6.js?v=5.1.1"></script>
<script data-cfasync="false" type="text/javascript" src="js/dist/menu_resizer.js?v=5.1.1"></script>
<script data-cfasync="false" type="text/javascript" src="js/dist/cross_framing_protection.js?v=5.1.1"></script>
<script data-cfasync="false" type="text/javascript" src="js/dist/rte.js?v=5.1.1"></script>
<script data-cfasync="false" type="text/javascript" src="js/vendor/tracekit.js?v=5.1.1"></script>
<script data-cfasync="false" type="text/javascript" src="js/dist/error_report.js?v=5.1.1"></script>
<script data-cfasync="false" type="text/javascript" src="js/messages.php?l=en&v=5.1.1&lang=en"></script>
<script data-cfasync="false" type="text/javascript" src="js/dist/config.js?v=5.1.1"></script>
<script data-cfasync="false" type="text/javascript" src="js/dist/doclinks.js?v=5.1.1"></script>
<script data-cfasync="false" type="text/javascript" src="js/dist/functions.js?v=5.1.1"></script>
<script data-cfasync="false" type="text/javascript" src="js/dist/navigation.js?v=5.1.1"></script>
<script data-cfasync="false" type="text/javascript" src="js/dist/indexes.js?v=5.1.1"></script>
<script data-cfasync="false" type="text/javascript" src="js/dist/common.js?v=5.1.1"></script>
<script data-cfasync="false" type="text/javascript" src="js/dist/page_settings.js?v=5.1.1"></script>
<script data-cfasync="false" type="text/javascript" src="js/dist/drag_drop_import.js?v=5.1.1"></script>
<script data-cfasync="false" type="text/javascript" src="js/dis