nginx
tcp/443
The following URL (usually /.git/config
) is publicly accessible and is leaking source code and repository configuration.
Severity: medium
Fingerprint: 2580fa947178c88602b1737db148c044b81b03713d63bb82370a6522e6bcee01
[core] repositoryformatversion = 0 filemode = true bare = false logallrefupdates = true [remote "origin"] url = git://git.moodle.org/moodle.git fetch = +refs/heads/*:refs/remotes/origin/* [branch "MOODLE_401_STABLE"] remote = origin merge = refs/heads/MOODLE_401_STABLE
The following Moodle application is publicly accessible and looks out-dated :
It is highly recommended to update to a safe version as soon as possible since multiple CVEs allow remote attackers to craft XSS attacks leading to code execution on the server.
If the application was already patched, reloading the web server to clear the PHP opcache will fix issue.
Reference:
Severity: high
Fingerprint: 0b591a20d83e9bbda3370ce58008084480080844800808448008084480080844
Found vulnerable Moodle application: Affected by CVE-2023-30943
Open service 85.214.60.71:443 · moodle.webionic.at
2024-12-22 07:11
HTTP/1.1 200 OK Server: nginx Date: Sun, 22 Dec 2024 07:11:10 GMT Content-Type: text/html; charset=utf-8 Transfer-Encoding: chunked Connection: close X-Powered-By: PHP/8.1.31 Content-Language: en Content-Script-Type: text/javascript Content-Style-Type: text/css X-UA-Compatible: IE=edge Cache-Control: no-store, no-cache, must-revalidate, post-check=0, pre-check=0, no-transform Pragma: no-cache Expires: Mon, 20 Aug 1969 09:23:00 GMT Accept-Ranges: none X-Frame-Options: sameorigin Set-Cookie: MoodleSession=9ktfe0s700l3q7aiuqjl8i6kvb; path=/; secure Last-Modified: Sun, 22 Dec 2024 07:11:10 GMT Vary: Accept-Encoding X-Powered-By: PleskLin
Open service 85.214.60.71:443 · moodle.webionic.at
2024-12-22 04:24
HTTP/1.1 200 OK Server: nginx Date: Sun, 22 Dec 2024 04:24:23 GMT Content-Type: text/html; charset=utf-8 Transfer-Encoding: chunked Connection: close X-Powered-By: PHP/8.1.31 Content-Language: en Content-Script-Type: text/javascript Content-Style-Type: text/css X-UA-Compatible: IE=edge Cache-Control: no-store, no-cache, must-revalidate, post-check=0, pre-check=0, no-transform Pragma: no-cache Expires: Mon, 20 Aug 1969 09:23:00 GMT Accept-Ranges: none X-Frame-Options: sameorigin Set-Cookie: MoodleSession=6or3ce6tsvkditccbuuk1kv9mm; path=/; secure Last-Modified: Sun, 22 Dec 2024 04:24:23 GMT Vary: Accept-Encoding X-Powered-By: PleskLin
Open service 85.214.60.71:443 · moodle.webionic.at
2024-12-20 07:58
HTTP/1.1 200 OK Server: nginx Date: Fri, 20 Dec 2024 07:58:53 GMT Content-Type: text/html; charset=utf-8 Transfer-Encoding: chunked Connection: close X-Powered-By: PHP/8.1.31 Content-Language: en Content-Script-Type: text/javascript Content-Style-Type: text/css X-UA-Compatible: IE=edge Cache-Control: no-store, no-cache, must-revalidate, post-check=0, pre-check=0, no-transform Pragma: no-cache Expires: Mon, 20 Aug 1969 09:23:00 GMT Accept-Ranges: none X-Frame-Options: sameorigin Set-Cookie: MoodleSession=pobaoqjkhtluaonp2evuip4f5e; path=/; secure Last-Modified: Fri, 20 Dec 2024 07:58:53 GMT Vary: Accept-Encoding X-Powered-By: PleskLin
Open service 85.214.60.71:443 · moodle.webionic.at
2024-12-20 06:05
HTTP/1.1 200 OK Server: nginx Date: Fri, 20 Dec 2024 06:05:39 GMT Content-Type: text/html; charset=utf-8 Transfer-Encoding: chunked Connection: close X-Powered-By: PHP/8.1.31 Content-Language: en Content-Script-Type: text/javascript Content-Style-Type: text/css X-UA-Compatible: IE=edge Cache-Control: no-store, no-cache, must-revalidate, post-check=0, pre-check=0, no-transform Pragma: no-cache Expires: Mon, 20 Aug 1969 09:23:00 GMT Accept-Ranges: none X-Frame-Options: sameorigin Set-Cookie: MoodleSession=e01o0n7jkv59039q666jc8c7l5; path=/; secure Last-Modified: Fri, 20 Dec 2024 06:05:39 GMT Vary: Accept-Encoding X-Powered-By: PleskLin
Open service 85.214.60.71:443 · moodle.webionic.at
2024-12-19 00:09
HTTP/1.1 200 OK Server: nginx Date: Thu, 19 Dec 2024 00:09:26 GMT Content-Type: text/html; charset=utf-8 Transfer-Encoding: chunked Connection: close X-Powered-By: PHP/8.1.31 Content-Language: en Content-Script-Type: text/javascript Content-Style-Type: text/css X-UA-Compatible: IE=edge Cache-Control: no-store, no-cache, must-revalidate, post-check=0, pre-check=0, no-transform Pragma: no-cache Expires: Mon, 20 Aug 1969 09:23:00 GMT Accept-Ranges: none X-Frame-Options: sameorigin Set-Cookie: MoodleSession=vqt610d4tan85krfiaupek01cg; path=/; secure Last-Modified: Thu, 19 Dec 2024 00:09:26 GMT Vary: Accept-Encoding X-Powered-By: PleskLin
Open service 85.214.60.71:443 · moodle.webionic.at
2024-12-18 19:46
HTTP/1.1 200 OK Server: nginx Date: Wed, 18 Dec 2024 19:46:10 GMT Content-Type: text/html; charset=utf-8 Transfer-Encoding: chunked Connection: close X-Powered-By: PHP/8.1.31 Content-Language: en Content-Script-Type: text/javascript Content-Style-Type: text/css X-UA-Compatible: IE=edge Cache-Control: no-store, no-cache, must-revalidate, post-check=0, pre-check=0, no-transform Pragma: no-cache Expires: Mon, 20 Aug 1969 09:23:00 GMT Accept-Ranges: none X-Frame-Options: sameorigin Set-Cookie: MoodleSession=8aklne9c6vqg6p2gp3hg2p6n90; path=/; secure Last-Modified: Wed, 18 Dec 2024 19:46:10 GMT Vary: Accept-Encoding X-Powered-By: PleskLin
Open service 85.214.60.71:443 · moodle.webionic.at
2024-12-14 06:28
HTTP/1.1 200 OK Server: nginx Date: Sat, 14 Dec 2024 06:28:52 GMT Content-Type: text/html; charset=utf-8 Transfer-Encoding: chunked Connection: close X-Powered-By: PHP/8.1.31 Content-Language: en Content-Script-Type: text/javascript Content-Style-Type: text/css X-UA-Compatible: IE=edge Cache-Control: no-store, no-cache, must-revalidate, post-check=0, pre-check=0, no-transform Pragma: no-cache Expires: Mon, 20 Aug 1969 09:23:00 GMT Accept-Ranges: none X-Frame-Options: sameorigin Set-Cookie: MoodleSession=u4ru94gg0sqduroiefloj65tdr; path=/; secure Last-Modified: Sat, 14 Dec 2024 06:28:52 GMT Vary: Accept-Encoding X-Powered-By: PleskLin
Open service 85.214.60.71:443 · moodle.webionic.at
2024-12-14 06:24
HTTP/1.1 200 OK Server: nginx Date: Sat, 14 Dec 2024 06:24:10 GMT Content-Type: text/html; charset=utf-8 Transfer-Encoding: chunked Connection: close X-Powered-By: PHP/8.1.31 Content-Language: en Content-Script-Type: text/javascript Content-Style-Type: text/css X-UA-Compatible: IE=edge Cache-Control: no-store, no-cache, must-revalidate, post-check=0, pre-check=0, no-transform Pragma: no-cache Expires: Mon, 20 Aug 1969 09:23:00 GMT Accept-Ranges: none X-Frame-Options: sameorigin Set-Cookie: MoodleSession=brthaht6rbdogedm8t0flq60sp; path=/; secure Last-Modified: Sat, 14 Dec 2024 06:24:10 GMT Vary: Accept-Encoding X-Powered-By: PleskLin
Open service 85.214.60.71:443 · moodle.webionic.at
2024-12-12 07:13
HTTP/1.1 200 OK Server: nginx Date: Thu, 12 Dec 2024 07:13:34 GMT Content-Type: text/html; charset=utf-8 Transfer-Encoding: chunked Connection: close X-Powered-By: PHP/8.1.31 Content-Language: en Content-Script-Type: text/javascript Content-Style-Type: text/css X-UA-Compatible: IE=edge Cache-Control: no-store, no-cache, must-revalidate, post-check=0, pre-check=0, no-transform Pragma: no-cache Expires: Mon, 20 Aug 1969 09:23:00 GMT Accept-Ranges: none X-Frame-Options: sameorigin Set-Cookie: MoodleSession=ple82c5df9vptkeu7fn9tkpd9t; path=/; secure Last-Modified: Thu, 12 Dec 2024 07:13:34 GMT Vary: Accept-Encoding X-Powered-By: PleskLin
Open service 85.214.60.71:443 · moodle.webionic.at
2024-12-12 02:54
HTTP/1.1 200 OK Server: nginx Date: Thu, 12 Dec 2024 02:54:22 GMT Content-Type: text/html; charset=utf-8 Transfer-Encoding: chunked Connection: close X-Powered-By: PHP/8.1.31 Content-Language: en Content-Script-Type: text/javascript Content-Style-Type: text/css X-UA-Compatible: IE=edge Cache-Control: no-store, no-cache, must-revalidate, post-check=0, pre-check=0, no-transform Pragma: no-cache Expires: Mon, 20 Aug 1969 09:23:00 GMT Accept-Ranges: none X-Frame-Options: sameorigin Set-Cookie: MoodleSession=nkogdn4nk2kd2lk1ovkllpsjms; path=/; secure Last-Modified: Thu, 12 Dec 2024 02:54:22 GMT Vary: Accept-Encoding X-Powered-By: PleskLin
Open service 85.214.60.71:443 · moodle.webionic.at
2024-12-02 22:51
HTTP/1.1 200 OK Server: nginx Date: Mon, 02 Dec 2024 22:51:05 GMT Content-Type: text/html; charset=utf-8 Transfer-Encoding: chunked Connection: close X-Powered-By: PHP/8.1.31 Content-Language: en Content-Script-Type: text/javascript Content-Style-Type: text/css X-UA-Compatible: IE=edge Cache-Control: no-store, no-cache, must-revalidate, post-check=0, pre-check=0, no-transform Pragma: no-cache Expires: Mon, 20 Aug 1969 09:23:00 GMT Accept-Ranges: none X-Frame-Options: sameorigin Set-Cookie: MoodleSession=trdlfrs9916gnmmfaa7qdgak2l; path=/; secure Last-Modified: Mon, 02 Dec 2024 22:51:05 GMT Vary: Accept-Encoding X-Powered-By: PleskLin
Open service 85.214.60.71:443 · moodle.webionic.at
2024-12-02 22:45
HTTP/1.1 200 OK Server: nginx Date: Mon, 02 Dec 2024 22:45:14 GMT Content-Type: text/html; charset=utf-8 Transfer-Encoding: chunked Connection: close X-Powered-By: PHP/8.1.31 Content-Language: en Content-Script-Type: text/javascript Content-Style-Type: text/css X-UA-Compatible: IE=edge Cache-Control: no-store, no-cache, must-revalidate, post-check=0, pre-check=0, no-transform Pragma: no-cache Expires: Mon, 20 Aug 1969 09:23:00 GMT Accept-Ranges: none X-Frame-Options: sameorigin Set-Cookie: MoodleSession=m7pojsup11123omeamq4urs9es; path=/; secure Last-Modified: Mon, 02 Dec 2024 22:45:14 GMT Vary: Accept-Encoding X-Powered-By: PleskLin
Open service 85.214.60.71:443 · moodle.webionic.at
2024-11-30 19:48
HTTP/1.1 200 OK Server: nginx Date: Sat, 30 Nov 2024 19:48:45 GMT Content-Type: text/html; charset=utf-8 Transfer-Encoding: chunked Connection: close X-Powered-By: PHP/8.1.31 Content-Language: en Content-Script-Type: text/javascript Content-Style-Type: text/css X-UA-Compatible: IE=edge Cache-Control: no-store, no-cache, must-revalidate, post-check=0, pre-check=0, no-transform Pragma: no-cache Expires: Mon, 20 Aug 1969 09:23:00 GMT Accept-Ranges: none X-Frame-Options: sameorigin Set-Cookie: MoodleSession=6pbtkk4o3lmakonuchenuo9tra; path=/; secure Last-Modified: Sat, 30 Nov 2024 19:48:45 GMT Vary: Accept-Encoding X-Powered-By: PleskLin
Open service 85.214.60.71:443 · moodle.webionic.at
2024-11-30 17:47
HTTP/1.1 200 OK Server: nginx Date: Sat, 30 Nov 2024 17:47:52 GMT Content-Type: text/html; charset=utf-8 Transfer-Encoding: chunked Connection: close X-Powered-By: PHP/8.1.31 Content-Language: en Content-Script-Type: text/javascript Content-Style-Type: text/css X-UA-Compatible: IE=edge Cache-Control: no-store, no-cache, must-revalidate, post-check=0, pre-check=0, no-transform Pragma: no-cache Expires: Mon, 20 Aug 1969 09:23:00 GMT Accept-Ranges: none X-Frame-Options: sameorigin Set-Cookie: MoodleSession=u3u9thlo8ddk4n9skbl2seg3i5; path=/; secure Last-Modified: Sat, 30 Nov 2024 17:47:52 GMT Vary: Accept-Encoding X-Powered-By: PleskLin
Open service 85.214.60.71:443 · moodle.webionic.at
2024-11-28 21:13
HTTP/1.1 200 OK Server: nginx Date: Thu, 28 Nov 2024 21:13:13 GMT Content-Type: text/html; charset=utf-8 Transfer-Encoding: chunked Connection: close X-Powered-By: PHP/8.1.31 Content-Language: en Content-Script-Type: text/javascript Content-Style-Type: text/css X-UA-Compatible: IE=edge Cache-Control: no-store, no-cache, must-revalidate, post-check=0, pre-check=0, no-transform Pragma: no-cache Expires: Mon, 20 Aug 1969 09:23:00 GMT Accept-Ranges: none X-Frame-Options: sameorigin Set-Cookie: MoodleSession=a4cm80utvbp8ba9mo5osd0eoc2; path=/; secure Last-Modified: Thu, 28 Nov 2024 21:13:13 GMT Vary: Accept-Encoding X-Powered-By: PleskLin
Open service 85.214.60.71:443 · moodle.webionic.at
2024-11-28 17:05
HTTP/1.1 200 OK Server: nginx Date: Thu, 28 Nov 2024 17:05:15 GMT Content-Type: text/html; charset=utf-8 Transfer-Encoding: chunked Connection: close X-Powered-By: PHP/8.1.31 Content-Language: en Content-Script-Type: text/javascript Content-Style-Type: text/css X-UA-Compatible: IE=edge Cache-Control: no-store, no-cache, must-revalidate, post-check=0, pre-check=0, no-transform Pragma: no-cache Expires: Mon, 20 Aug 1969 09:23:00 GMT Accept-Ranges: none X-Frame-Options: sameorigin Set-Cookie: MoodleSession=asi5t7m3mghtfnsj7vvfhukb1v; path=/; secure Last-Modified: Thu, 28 Nov 2024 17:05:15 GMT Vary: Accept-Encoding X-Powered-By: PleskLin
Open service 85.214.60.71:443 · moodle.webionic.at
2024-11-26 22:06
HTTP/1.1 200 OK Server: nginx Date: Tue, 26 Nov 2024 22:06:43 GMT Content-Type: text/html; charset=utf-8 Transfer-Encoding: chunked Connection: close X-Powered-By: PHP/8.1.30 Content-Language: en Content-Script-Type: text/javascript Content-Style-Type: text/css X-UA-Compatible: IE=edge Cache-Control: no-store, no-cache, must-revalidate, post-check=0, pre-check=0, no-transform Pragma: no-cache Expires: Mon, 20 Aug 1969 09:23:00 GMT Accept-Ranges: none X-Frame-Options: sameorigin Set-Cookie: MoodleSession=d0ag19km0ra3080lbv75j07o10; path=/; secure Last-Modified: Tue, 26 Nov 2024 22:06:43 GMT Vary: Accept-Encoding X-Powered-By: PleskLin
Open service 85.214.60.71:443 · moodle.webionic.at
2024-11-26 18:22
HTTP/1.1 200 OK Server: nginx Date: Tue, 26 Nov 2024 18:22:12 GMT Content-Type: text/html; charset=utf-8 Transfer-Encoding: chunked Connection: close X-Powered-By: PHP/8.1.30 Content-Language: en Content-Script-Type: text/javascript Content-Style-Type: text/css X-UA-Compatible: IE=edge Cache-Control: no-store, no-cache, must-revalidate, post-check=0, pre-check=0, no-transform Pragma: no-cache Expires: Mon, 20 Aug 1969 09:23:00 GMT Accept-Ranges: none X-Frame-Options: sameorigin Set-Cookie: MoodleSession=qrg48lfnf1vena4os2c2c7djqp; path=/; secure Last-Modified: Tue, 26 Nov 2024 18:22:12 GMT Vary: Accept-Encoding X-Powered-By: PleskLin
Open service 85.214.60.71:443 · moodle.webionic.at
2024-11-20 21:48
HTTP/1.1 200 OK Server: nginx Date: Wed, 20 Nov 2024 21:48:11 GMT Content-Type: text/html; charset=utf-8 Transfer-Encoding: chunked Connection: close X-Powered-By: PHP/8.1.30 Content-Language: en Content-Script-Type: text/javascript Content-Style-Type: text/css X-UA-Compatible: IE=edge Cache-Control: no-store, no-cache, must-revalidate, post-check=0, pre-check=0, no-transform Pragma: no-cache Expires: Mon, 20 Aug 1969 09:23:00 GMT Accept-Ranges: none X-Frame-Options: sameorigin Set-Cookie: MoodleSession=cjhv7d2ghbkmqh2tvj0p22uc4m; path=/; secure Last-Modified: Wed, 20 Nov 2024 21:48:11 GMT Vary: Accept-Encoding X-Powered-By: PleskLin
Open service 85.214.60.71:443 · moodle.webionic.at
2024-11-20 20:09
HTTP/1.1 200 OK Server: nginx Date: Wed, 20 Nov 2024 20:09:41 GMT Content-Type: text/html; charset=utf-8 Transfer-Encoding: chunked Connection: close X-Powered-By: PHP/8.1.30 Content-Language: en Content-Script-Type: text/javascript Content-Style-Type: text/css X-UA-Compatible: IE=edge Cache-Control: no-store, no-cache, must-revalidate, post-check=0, pre-check=0, no-transform Pragma: no-cache Expires: Mon, 20 Aug 1969 09:23:00 GMT Accept-Ranges: none X-Frame-Options: sameorigin Set-Cookie: MoodleSession=bgg894ue88ku8qbomqi1mchjlc; path=/; secure Last-Modified: Wed, 20 Nov 2024 20:09:41 GMT Vary: Accept-Encoding X-Powered-By: PleskLin