nginx 1.24.0
tcp/443
The following URL (usually /.git/config) is publicly accessible and is leaking source code and repository configuration.
Severity: medium
Fingerprint: 2580fa947178c88602b1737db148c044b81b03713d63bb82370a652272caf41d
[core] repositoryformatversion = 0 filemode = true bare = false logallrefupdates = true [remote "origin"] url = https://github.com/Almajdouie-Web-Team/sa.edu.meli.git fetch = +refs/heads/*:refs/remotes/origin/* [branch "main"] remote = origin merge = refs/heads/main [branch "master"] remote = origin merge = refs/heads/master
Open service 20.33.66.137:443 ยท beta.meli.edu.sa
2026-01-08 10:56
HTTP/1.1 200 OK Server: nginx/1.24.0 (Ubuntu) Content-Type: text/html; charset=UTF-8 Transfer-Encoding: chunked Connection: close Vary: Accept-Encoding Cache-Control: no-cache, private Date: Thu, 08 Jan 2026 10:57:59 GMT Set-Cookie: XSRF-TOKEN=eyJpdiI6ImlRU3ZVN2ZSaEh3NU1YZEFvc3B3VVE9PSIsInZhbHVlIjoiczhLQjFPYWNqY3NDOVZ0YWp2bTU3T2NCR3c1eWhIN3dlazc4R2ZmK1lkdFBMckxKbG85K0d4UGl0TVJGeGFrdGI3a0xxTWxMWlUvam1FUE1FWmZoK0p3RVhOTVVZTjNGOWlpUzR5dXJYMHRINmgxb2N3RWk3T1QzczY2aUJ0TlUiLCJtYWMiOiIwODhmZjg1ZTYwYWYyMGY5YzM4NzAxM2Y2MDBmY2ZjMTI3OWExMzliZTc0Y2E0YzUwZGMzMmFkZTEzNzI2N2IwIiwidGFnIjoiIn0%3D; expires=Thu, 08 Jan 2026 12:57:59 GMT; Max-Age=7200; path=/; secure; samesite=lax Set-Cookie: meli_beta_session=eyJpdiI6Ikl3NE5sT1cwVGxyVlVyT0J3b29UTlE9PSIsInZhbHVlIjoibEExd1FkdzlhSTlBYndHZ0YveWxkUjdpVGFvVmpLdzBGbDhFREZYbDdMUDUxT3ExUjROU3pucmNIVU5HLzhGaVQycmZJTXVRM2RRQXdVU1NHTUhkUEE1NXdWRERwcEdYM1hvRVdsZWhWQUV3MS9WdWRsTjRJaWVpRXlHMDNRSG0iLCJtYWMiOiI2MjQ4M2VhOGQyYzViYjM5Mjk1NTdiOThmYjU3MTBhODg4YzQ2OTUxMDk4MTc4NmQ0MTg4MjJhODAzYzRjODkzIiwidGFnIjoiIn0%3D; expires=Thu, 08 Jan 2026 12:57:59 GMT; Max-Age=7200; path=/; httponly; samesite=lax X-Frame-Options: SAMEORIGIN Strict-Transport-Security: max-age=31536000; includeSubDomains; preload X-Content-Type-Options: nosniff X-XSS-Protection: 1; mode=block Referrer-Policy: no-referrer