The server-status page (usually /server-status) allows server administrators to find out how well their server is performing.
This is a HTML page that gives the current server statistics such as the server version, up time,cpu, ram, and information about requests made to the server.
This information can be very useful if the application is sent sensitive information as GET requests. If you monitor this page you might be able to find CSRF tokens, API keys, hidden paths, and other sensitive information being sent to the server.
https://medium.com/@ghostlulzhacks/apache-server-status-a70abed83f5a
Severity: medium
Fingerprint: ee80c6706842d3ef6842d3ef6325bb316325bb31c9dbc500c9dbc500ad541e66
Apache Status Apache Server Status for lp.axis-electronique.com (via 127.0.0.1) Server Version: Apache/2.4.62 (Debian) Server MPM: event Server Built: 2024-10-04T15:21:08 Current Time: Tuesday, 21-Jan-2025 16:56:50 CET Restart Time: Tuesday, 21-Jan-2025 16:55:34 CET Parent Server Config. Generation: 1 Parent Server MPM Generation: 0 Server uptime: 1 minute 16 seconds Server load: 8.63 10.79 13.25 Total accesses: 327 - Total Traffic: 1.4 MB - Total Duration: 27404 CPU Usage: u.16 s.09 cu0 cs0 - .329% CPU load 4.3 requests/sec - 19.0 kB/second - 4515 B/request - 83.8043 ms/request 1 requests currently being processed, 0 workers gracefully restarting, 49 idle workers SlotPIDStoppingConnections ThreadsAsync connections totalacceptingbusygracefulidlewritingkeep-aliveclosing 0928834no0yes0025000 1928835no1yes1024000 Sum201 1049000 _________________________________W________________.............. ................................................................ ...................... Scoreboard Key: "_" Waiting for Connection, "S" Starting up, "R" Reading Request, "W" Sending Reply, "K" Keepalive (read), "D" DNS Lookup, "C" Closing connection, "L" Logging, "G" Gracefully finishing, "I" Idle cleanup of worker, "." Open slot with no current process SrvPIDAccMCPU SSReqDurConnChildSlotClientProtocolVHostRequest 0-09288340/10/10_ 0.150012390.00.040.04 127.0.0.1http/1.1lp.axis-electronique.com:8080GET /v2/_catalog HTTP/1.1 0-09288340/7/7_ 0.1301232210.00.010.01 127.0.0.1http/1.1go.modulo.io:8080POST /mtc/event HTTP/1.1 0-09288340/8/8_ 0.1301223200.00.050.05 127.0.0.1http/1.1go.modulo.io:8080POST /mtc/event HTTP/1.1 0-09288340/8/8_ 0.14403980.00.060.06 127.0.0.1http/1.1localhost:8080OPTIONS / HTTP/1.0 0-09288340/11/11_ 0.150018910.00.100.10 127.0.0.1http/1.1lp.axis-electronique.com:8080GET /actuator/env HTTP/1.1 0-09288340/8/8_ 0.13005880.00.030.03 127.0.0.1http/1.1localhost:8080OPTIONS / HTTP/1.0 0-09288340/7/7_ 0.14101620.00.010.01 127.0.0.1http/1.1localhost:8080OPTIONS / HTTP/1.0 0-09288340/7/7_ 0.1201742650.00.010.01 127.0.0.1http/1.1go.modulo.io:8080POST /mtc/event HTTP/1.1 0-09288340/9/9_ 0.12002290.00.010.01 127.0.0.1http/1.1localhost:8080OPTIONS / HTTP/1.0 0-09288340/8/8_ 0.13257720.00.010.01 127.0.0.1http/1.1news.melangesdesalpes.com:8080OPTIONS /mtc/event HTTP/1.1 0-09288340/9/9_ 0.14005250.00.040.04 127.0.0.1http/1.1lp.axis-electronique.com:8080GET / HTTP/1.1 0-09288340/10/10_ 0.15005000.00.010.01 127.0.0.1http/1.1lp.axis-electronique.com:8080GET / HTTP/1.1 0-09288340/6/6_ 0.1501432580.00.030.03 127.0.0.1http/1.1go.modulo.io:8080POST /mtc/event HTTP/1.1 0-09288340/9/9_ 0.1505988210.00.010.01 127.0.0.1http/1.1go.ensao.fr:8080GET /email/678fc3b56ced1281408090.gif HTTP/1.1 0-09288340/7/7_ 0.1501275380.00.040.04 127.0.0.1http/1.1go.modulo.io:8080POST /mtc/event HTTP/1.1 0-09288340/5/5_ 0.110468600.00.010.01 127.0.0.1http/1.1crm.oceanadventure.surf:8080GET /mtracking.gif?page_title=Kitesurf%20Camp%20Dakhla%20N%C2%B 0-09288340/10/10_ 0.144012930.00.040.04 127.0.0.1http/1.1localhost:8080OPTIONS / HTTP/1.0 0-09288340/8/8_ 0.150016180.00.050.05 127.0.0.1http/1.1lp.axis-electronique.com:8080GET /server HTTP/1.1 0-09288340/7/7_ 0.1201854460.00.010.01 127.0.0.1http/1.1go.modulo.io:8080POST /mtc/event HTTP/1.1 0-09288340/5/5_ 0.14264690.00.030.03 127.0.0.1http/1.1go.hellomoov.com:8080GET /mtc.js HTTP/1.1 0-09288340/7/7_ 0.1301665700.00.010.01 127.0.0.1http/1.1go.modulo.io:8080POST /mtc/event HTTP/1.1 0-09288340/8/8_ 0.150012060.00.040.04 127.0.0.1http/1.1lp.axis-electronique.com:8080GET /ecp/Current/exporttool/microsoft.exchange.ediscovery.expor 0-09288340/6/6_ 0.1242324180.00.010.01 127.0.0.1http/1.1go.modulo.io:8080POST /mtc/event HTTP/1.1 0-09288340/8/8_ 0.142021880.00.060.06 127.0.0.1http/1.1localhost:8080OPTIONS / HTTP/1.0 0-09288340/7/7_ 0.08008070.00.010.01 127.0.0.1http/1.1localhost:8080OPTIONS / HTTP/1.0 1-09288350/5/5_ 0.0901258180.00.030.03 127.0.0.1http/1.1go.modulo.io:8080POST /mtc/event HTTP/1.1 1-09288350/4/4_ 0.080602140.00.030.03 127.0.0.1http/1.1marketing.capillum.fr:8080GET /mtc.js HTTP/1.1 1-09288350/5/5_ 0.10001950.00.010.01 127.0.0.1http/1.1lp.axis-electronique.com:8080GET /.vscode/sftp.json HTTP/1.1 1-09288350/7/7_ 0.10001750.00.030.03 127.0.0.1http/1.1localhost:8080OPTIONS / HTTP/1.0 1-09288350/6/6_ 0.09006530.00.030.03 127.0.0.1http/1.1localhost:8080OPTIONS / HTTP/1.0 1-09288350/7/7_ 0.090533980.00.010.01 127.0.0.1http/1.1marketing.capillum.fr:8080GET /mtracking.gif?page_title=Capillum%C2%AE%20-%20Espace%20mem 1-09288350/6/6_ 0.100070.00.000.00 127.0.0.1http/1.1lp.axis-electronique.com:8080GET /about HTTP/1.1 1-09288350/3/3_ 0.0900380.00.000.00 127.0.0.1http/1.1localhost:8080OPTIONS / HTTP/1.0 1-09288351/7/7W 0.09003200.00.010.01 127.0.0.1http/1.1lp.axis-electronique.com:8080GET /server-status HTTP/1.1 1-09288350/5/5_ 0.10002970.00.030.03 127.0.0.1http/1.1localhost:8080OPTIONS / HTTP/1.0 1-09288350/6/6_ 0.080514960.00.040.04 127.0.0.1http/1.1crm.oceanadventure.surf:8080OPTIONS /mtc/event HTTP/1.1 1-09288350/4/4_ 0.090592660.00.030.03 127.0.0.1http/1.1marketing.capillum.fr:8080GET /mtc.js HTTP/1.1 1-09288350/3/3_ 0.10097970.00.030.03 127.0.0.1http/1.1go.modulo.io:8080GET /mtc.js HTTP/1.1 1-09288350/3/3_ 0.0900120.00.000.00 127.0.0.1http/1.1localhost:8080OPTIONS / HTTP/1.0 1-09288350/6/6_ 0.09002720.00.030.03 127.0.0.1http/1.1localhost:8080OPTIONS / HTTP/1.0 1-09288350/6/6_ 0.10001440.00.100.10 127.0.0.1http/1.1go.ensao.fr:8080GET /media/images/1-9-1-683x1024.jpg HTTP/1.1 1-09288350/3/3_ 0.06137710.00.000.00 127.0.0.1http/1.1go.modulo.io:8080GET /mtc?mautic_device_id=rcojffffjb8hxl1sk50pxc2 HTTP/1.1 1-09288350/8/8_ 0.10001340.00.030.03 127.0.0.1http/1.1lp.axis-electronique.com:8080GET /debug/default/view?panel=config HTTP/1.1 1-09288350/7/7_ 0.1001414400.00.060.06 127.0.0.1http/1.1go.modulo.io:8080POST /mtc/event HTTP/1.1 1-09288350/6/6_ 0.09006660.00.030.03 127.0.0.1http/1.1localhost:8080OPTIONS / HTTP/1.0 1-09288350/5/5_ 0.100010810.00.070.07 127.0.0.1http/1.1go.ensao.fr:8080GET /themes/archive/assets/logo.png?v8ada51c4 HTTP/1.1 1-09288350/2/2_ 0.1001631640.00.020.02 127.0.0.1http/1.1go.modulo.io:8080POST /mtc/event HTTP/1.1 1-09288350/5/5_ 0.1001533210.00.010.01 127.0.0.1http/1.1go.modulo.io:8080POST /mtc/event HTTP/1.1 1-09288350/7/7_ 0.10006510.00.010.01 127.0.0.1http/1.1lp.axis-electronique.com:8080GET /version HTTP/1.1 1-09288350/6/6_ 0.1001322490.00.040.04 127.0.0.1http/1.1go.modulo.io:8080POST /mtc/event HTTP/1.1 SrvChild Server number - generation PIDOS process ID AccNumber of accesses this connection / this child / this slot MMode of operation CPUCPU usage, number of seconds SS<
The following URL (usually /.git/config) is publicly accessible and is leaking source code and repository configuration.
Severity: medium
Fingerprint: 2580fa947178c88602b1737db148c044b81b03713d63bb82370a6522d48194a7
[core] repositoryformatversion = 0 filemode = true bare = false logallrefupdates = true [submodule] active = . [remote "origin"] url = /var/www/local/lp.axis-electronique.com.maas.webanyone.net/repo/. fetch = +refs/heads/*:refs/remotes/origin/* [submodule "mautic-whitelabeler"] url = https://github.com/nickian/mautic-whitelabeler.git