Apache
tcp/443 tcp/80
The following URL (usually /.git/config) is publicly accessible and is leaking source code and repository configuration.
Severity: medium
Fingerprint: 2580fa947178c88602b1737db148c044b81b03713d63bb82370a6522676c0e50
[core] repositoryformatversion = 0 filemode = true bare = false logallrefupdates = true [remote "origin"] url = https://github.com/MakeGravityDev/manifestgenerator.git fetch = +refs/heads/*:refs/remotes/origin/* [branch "main"] remote = origin merge = refs/heads/main
Severity: medium
Fingerprint: 2580fa947178c88602b1737db148c044b81b03713d63bb82370a6522557bac8f
[core] repositoryformatversion = 0 filemode = true bare = false logallrefupdates = true [remote "origin"] url = https://github.com/MakeGravityDev/manifestgenerator.git fetch = +refs/heads/*:refs/remotes/origin/*
The following URL (usually /.git/config) is publicly accessible and is leaking source code and repository configuration.
Severity: medium
Fingerprint: 2580fa947178c88602b1737db148c044b81b03713d63bb82370a6522676c0e50
[core] repositoryformatversion = 0 filemode = true bare = false logallrefupdates = true [remote "origin"] url = https://github.com/MakeGravityDev/manifestgenerator.git fetch = +refs/heads/*:refs/remotes/origin/* [branch "main"] remote = origin merge = refs/heads/main
Severity: medium
Fingerprint: 2580fa947178c88602b1737db148c044b81b03713d63bb82370a6522557bac8f
[core] repositoryformatversion = 0 filemode = true bare = false logallrefupdates = true [remote "origin"] url = https://github.com/MakeGravityDev/manifestgenerator.git fetch = +refs/heads/*:refs/remotes/origin/*
Exposing Swagger/OpenAPI documentation is primarily a risk if your API has underlying security flaws, as it gives attackers a precise roadmap to find them.
Those detail every endpoint, parameter, and data model, making it easier to discover and exploit vulnerabilities like broken access control or injection points.
While a perfectly secure API mitigates the danger, protecting your documentation is a critical layer of defense that forces attackers to work without a map.
Severity: info
Fingerprint: 5733ddf49ff49cd1b885ff43ea214a0321c6a0e2260deae8fbb4bd8463a8194b
Public Swagger UI/API detected at path: /swagger.json - sample paths:
GET /api/categorydepartmentmapping?page=1&limit=5&category=22
GET /api/integration/managecolumns
GET /api/manifestGroup/delete?id={id}
GET /api/manifestGroup/view?id={id}
GET /api/settings/get_upc_sequence_queue
GET /api/settings/print_settings_index
GET /api/settings/scan_settings_index
GET /api/user
GET /api/user/delete?id={id}
GET /api/user/edit?id={id}
GET /api/user/getproductimage?id=
GET /api/user/getproductimage_for_edit?id=
POST /api/auction
POST /api/auction/actionCreateArray
POST /api/auction/actionGen_thumbnail
POST /api/auction/add_image_to_stock
POST /api/auction/addquantity
POST /api/auction/auction_product_items
POST /api/auction/auction_products
POST /api/auction/auction_zpl_templates
POST /api/auction/categories
POST /api/auction/change_product_condition
POST /api/auction/check_nonupc_lot
POST /api/auction/create
POST /api/auction/delete?id={id}
POST /api/auction/delete_product
POST /api/auction/deleteimg
POST /api/auction/deleteproductimgs
POST /api/auction/deleteproductquantity
POST /api/auction/departments
POST /api/auction/editProduct
POST /api/auction/editProductItem
POST /api/auction/get_auction_data_settings?auction_id={47}
POST /api/auction/get_data_settings
POST /api/auction/get_new_lot
POST /api/auction/get_thumbnail
POST /api/auction/getproduct
POST /api/auction/getproduct_thumbnail
POST /api/auction/getupc_fetch
POST /api/auction/item
POST /api/auction/itemconditions
POST /api/auction/notes
POST /api/auction/noupc
POST /api/auction/remove_image_from_stock
POST /api/auction/saveUpc
POST /api/auction/update
POST /api/auction/update_auction_data_settings
POST /api/auction/uploadimage
POST /api/auction/zpltemplates
POST /api/auth/login
POST /api/categorydepartmentmapping/create
POST /api/categorydepartmentmapping/update
POST /api/common/get_data_settings
POST /api/common/upc_search
POST /api/integration/updatecolumns
POST /api/manifestGroup
POST /api/manifestGroup/create
POST /api/manifestGroup/datassetings
POST /api/manifestGroup/update
POST /api/settings/update_print_settings
POST /api/settings/update_scan_settings
POST /api/settings/view_scan_settings?id={id}
POST /api/user/add
Exposing Swagger/OpenAPI documentation is primarily a risk if your API has underlying security flaws, as it gives attackers a precise roadmap to find them.
Those detail every endpoint, parameter, and data model, making it easier to discover and exploit vulnerabilities like broken access control or injection points.
While a perfectly secure API mitigates the danger, protecting your documentation is a critical layer of defense that forces attackers to work without a map.
Severity: info
Fingerprint: 5733ddf49ff49cd1b885ff43ea214a0321c6a0e2260deae8fbb4bd8463a8194b
Public Swagger UI/API detected at path: /swagger.json - sample paths:
GET /api/categorydepartmentmapping?page=1&limit=5&category=22
GET /api/integration/managecolumns
GET /api/manifestGroup/delete?id={id}
GET /api/manifestGroup/view?id={id}
GET /api/settings/get_upc_sequence_queue
GET /api/settings/print_settings_index
GET /api/settings/scan_settings_index
GET /api/user
GET /api/user/delete?id={id}
GET /api/user/edit?id={id}
GET /api/user/getproductimage?id=
GET /api/user/getproductimage_for_edit?id=
POST /api/auction
POST /api/auction/actionCreateArray
POST /api/auction/actionGen_thumbnail
POST /api/auction/add_image_to_stock
POST /api/auction/addquantity
POST /api/auction/auction_product_items
POST /api/auction/auction_products
POST /api/auction/auction_zpl_templates
POST /api/auction/categories
POST /api/auction/change_product_condition
POST /api/auction/check_nonupc_lot
POST /api/auction/create
POST /api/auction/delete?id={id}
POST /api/auction/delete_product
POST /api/auction/deleteimg
POST /api/auction/deleteproductimgs
POST /api/auction/deleteproductquantity
POST /api/auction/departments
POST /api/auction/editProduct
POST /api/auction/editProductItem
POST /api/auction/get_auction_data_settings?auction_id={47}
POST /api/auction/get_data_settings
POST /api/auction/get_new_lot
POST /api/auction/get_thumbnail
POST /api/auction/getproduct
POST /api/auction/getproduct_thumbnail
POST /api/auction/getupc_fetch
POST /api/auction/item
POST /api/auction/itemconditions
POST /api/auction/notes
POST /api/auction/noupc
POST /api/auction/remove_image_from_stock
POST /api/auction/saveUpc
POST /api/auction/update
POST /api/auction/update_auction_data_settings
POST /api/auction/uploadimage
POST /api/auction/zpltemplates
POST /api/auth/login
POST /api/categorydepartmentmapping/create
POST /api/categorydepartmentmapping/update
POST /api/common/get_data_settings
POST /api/common/upc_search
POST /api/integration/updatecolumns
POST /api/manifestGroup
POST /api/manifestGroup/create
POST /api/manifestGroup/datassetings
POST /api/manifestGroup/update
POST /api/settings/update_print_settings
POST /api/settings/update_scan_settings
POST /api/settings/view_scan_settings?id={id}
POST /api/user/add
Open service 45.76.233.35:443 · mfs.manyfastscan.com
2026-01-09 17:09
HTTP/1.1 302 Found Date: Fri, 09 Jan 2026 17:09:35 GMT Server: Apache Set-Cookie: PHPSESSID=bq0v9tagjqqqjjjd3htn97n2gg; path=/ Expires: Thu, 19 Nov 1981 08:52:00 GMT Cache-Control: no-store, no-cache, must-revalidate Pragma: no-cache Location: https://mfs.manyfastscan.com/site/login Content-Length: 0 Connection: close Content-Type: text/html; charset=UTF-8
Open service 45.76.233.35:80 · mfs.manyfastscan.com
2026-01-09 17:09
HTTP/1.1 302 Found Date: Fri, 09 Jan 2026 17:10:14 GMT Server: Apache Set-Cookie: PHPSESSID=frikpgomhgsvk8sie5o107ae07; path=/ Expires: Thu, 19 Nov 1981 08:52:00 GMT Cache-Control: no-store, no-cache, must-revalidate Pragma: no-cache Location: http://mfs.manyfastscan.com/site/login Content-Length: 0 Connection: close Content-Type: text/html; charset=UTF-8
Open service 45.76.233.35:443 · mfs.manyfastscan.com
2026-01-02 23:29
HTTP/1.1 302 Found Date: Fri, 02 Jan 2026 23:29:37 GMT Server: Apache Set-Cookie: PHPSESSID=1hli66pca9tebujkm4mlau0qir; path=/ Expires: Thu, 19 Nov 1981 08:52:00 GMT Cache-Control: no-store, no-cache, must-revalidate Pragma: no-cache Location: https://mfs.manyfastscan.com/site/login Content-Length: 0 Connection: close Content-Type: text/html; charset=UTF-8
Open service 45.76.233.35:80 · mfs.manyfastscan.com
2025-12-30 09:40
HTTP/1.1 302 Found Date: Tue, 30 Dec 2025 09:40:07 GMT Server: Apache Set-Cookie: PHPSESSID=uej00dn893auibqbhjvmaum8i3; path=/ Expires: Thu, 19 Nov 1981 08:52:00 GMT Cache-Control: no-store, no-cache, must-revalidate Pragma: no-cache Location: http://mfs.manyfastscan.com/site/login Content-Length: 0 Connection: close Content-Type: text/html; charset=UTF-8
Open service 45.76.233.35:443 · mfs.manyfastscan.com
2025-12-30 09:40
HTTP/1.1 302 Found Date: Tue, 30 Dec 2025 09:40:07 GMT Server: Apache Set-Cookie: PHPSESSID=c3qebotj8motu7df5mvnbvtdfp; path=/ Expires: Thu, 19 Nov 1981 08:52:00 GMT Cache-Control: no-store, no-cache, must-revalidate Pragma: no-cache Location: https://mfs.manyfastscan.com/site/login Content-Length: 0 Connection: close Content-Type: text/html; charset=UTF-8
Open service 45.76.233.35:443 · mfs.manyfastscan.com
2025-12-23 09:19
HTTP/1.1 302 Found Date: Tue, 23 Dec 2025 09:19:30 GMT Server: Apache Set-Cookie: PHPSESSID=8blb34dv3hop5qr0jqut0kcier; path=/ Expires: Thu, 19 Nov 1981 08:52:00 GMT Cache-Control: no-store, no-cache, must-revalidate Pragma: no-cache Location: https://mfs.manyfastscan.com/site/login Content-Length: 0 Connection: close Content-Type: text/html; charset=UTF-8
Open service 45.76.233.35:80 · mfs.manyfastscan.com
2025-12-22 22:05
HTTP/1.1 302 Found Date: Mon, 22 Dec 2025 22:05:56 GMT Server: Apache Set-Cookie: PHPSESSID=plng6s50hf83vpak5ql00ffok1; path=/ Expires: Thu, 19 Nov 1981 08:52:00 GMT Cache-Control: no-store, no-cache, must-revalidate Pragma: no-cache Location: http://mfs.manyfastscan.com/site/login Content-Length: 0 Connection: close Content-Type: text/html; charset=UTF-8
Open service 45.76.233.35:443 · mfs.manyfastscan.com
2025-12-21 11:22
HTTP/1.1 302 Found Date: Sun, 21 Dec 2025 11:22:51 GMT Server: Apache Set-Cookie: PHPSESSID=cvp0n68okdaatltjqumad9ckl1; path=/ Expires: Thu, 19 Nov 1981 08:52:00 GMT Cache-Control: no-store, no-cache, must-revalidate Pragma: no-cache Location: https://mfs.manyfastscan.com/site/login Content-Length: 0 Connection: close Content-Type: text/html; charset=UTF-8
Open service 45.76.233.35:80 · mfs.manyfastscan.com
2025-12-21 04:05
HTTP/1.1 302 Found Date: Sun, 21 Dec 2025 04:05:33 GMT Server: Apache Set-Cookie: PHPSESSID=328ngin272t53vslomhkrlt12p; path=/ Expires: Thu, 19 Nov 1981 08:52:00 GMT Cache-Control: no-store, no-cache, must-revalidate Pragma: no-cache Location: http://mfs.manyfastscan.com/site/login Content-Length: 0 Connection: close Content-Type: text/html; charset=UTF-8
Open service 45.76.233.35:443 · mfs.manyfastscan.com
2025-12-19 07:05
HTTP/1.1 302 Found Date: Fri, 19 Dec 2025 07:05:13 GMT Server: Apache Set-Cookie: PHPSESSID=4ancbugvjj3vhom71pf0bber64; path=/ Expires: Thu, 19 Nov 1981 08:52:00 GMT Cache-Control: no-store, no-cache, must-revalidate Pragma: no-cache Location: https://mfs.manyfastscan.com/site/login Content-Length: 0 Connection: close Content-Type: text/html; charset=UTF-8
Open service 45.76.233.35:80 · mfs.manyfastscan.com
2025-12-19 02:24
HTTP/1.1 302 Found Date: Fri, 19 Dec 2025 02:24:34 GMT Server: Apache Set-Cookie: PHPSESSID=ms8hr19mpvqtlgrgfau9skgn3t; path=/ Expires: Thu, 19 Nov 1981 08:52:00 GMT Cache-Control: no-store, no-cache, must-revalidate Pragma: no-cache Location: http://mfs.manyfastscan.com/site/login Content-Length: 0 Connection: close Content-Type: text/html; charset=UTF-8