The following URL (usually /.git/config
) is publicly accessible and is leaking source code and repository configuration.
Severity: high
Fingerprint: 2580fa947178c88602b1737db148c044b81b03713d63bb82370a6522e9fbe215
[core] repositoryformatversion = 0 filemode = true bare = false logallrefupdates = true [remote "origin"] url = https://webwaylab@bitbucket.org/webwaylab/priem-akkumulyatorov.ru.git fetch = +refs/heads/*:refs/remotes/origin/* [remote "shamshin_a"] url = https://shamalex@bitbucket.org/webwaylab/priem-akkumulyatorov.ru.git fetch = +refs/heads/*:refs/remotes/shamshin_a/* [user] email = shmashin.alexandr@gmail.com name = shamshin alex [branch "master"] remote = shamshin_a merge = refs/heads/master
Severity: high
Fingerprint: 2580fa947e78dd08e645819d0eff380e4f0bd5818241b0805bb2979ac27a721f
HTTP/1.1 200 OK Server: nginx Date: Tue, 09 May 2023 00:38:33 GMT Content-Type: text/html; charset=UTF-8 Transfer-Encoding: chunked Connection: close Vary: Accept-Encoding X-Powered-By: PHP/5.6.36 P3P: policyref="/bitrix/p3p.xml", CP="NON DSP COR CUR ADM DEV PSA PSD OUR UNR BUS UNI COM NAV INT DEM STA" X-Powered-CMS: Bitrix Site Manager (3cc2f60b30a1436dcebe90fb0d23eeba) Expires: Thu, 19 Nov 1981 08:52:00 GMT Cache-Control: no-store, no-cache, must-revalidate, post-check=0, pre-check=0 Pragma: no-cache Set-Cookie: PHPSESSID=e2d4a38b3ec1bc2f49b5f5b0d50ef705; path=/; HttpOnly Cache-Control: max-age=172800, private, must-revalidate Strict-Transport-Security: max-age=31536000; Page title: Прием аккумуляторов Б/У – сдать АКБ дорого в пункт приема в Москве[core] repositoryformatversion = 0 filemode = true bare = false logallrefupdates = true [remote "origin"] url = https://webwaylab@bitbucket.org/webwaylab/priem-akkumulyatorov.ru.git fetch = +refs/heads/*:refs/remotes/origin/* [remote "shamshin_a"] url = https://shamalex@bitbucket.org/webwaylab/priem-akkumulyatorov.ru.git fetch = +refs/heads/*:refs/remotes/shamshin_a/* [user] email = shmashin.alexandr@gmail.com name = shamshin alex [branch "master"] remote = shamshin_a merge = refs/heads/master