Apache
tcp/443
The following URL (usually /.git/config) is publicly accessible and is leaking source code and repository configuration.
Severity: medium
Fingerprint: 2580fa947178c88602b1737db148c044baa2727ab8135b5bbc521bbbf243ce0a
[core] repositoryformatversion = 0 filemode = false bare = false logallrefupdates = true symlinks = false ignorecase = true [remote "origin"] url = https://gitee.com/heyingmin/vueadmin-thinkphp.git fetch = +refs/heads/*:refs/remotes/origin/* [branch "master"] remote = origin merge = refs/heads/master
Open service 8.208.90.19:443 · www.wingwahromford.co.uk
2026-01-02 12:32
HTTP/1.1 200 OK Date: Fri, 02 Jan 2026 12:32:38 GMT Server: Apache Access-Control-Allow-Credentials: true Access-Control-Max-Age: 1800 Access-Control-Allow-Methods: GET, POST, PATCH, PUT, DELETE, OPTIONS Access-Control-Allow-Headers: Authorization, Content-Type, If-Match, If-Modified-Since, If-None-Match, If-Unmodified-Since, X-CSRF-TOKEN, X-Requested-With Access-Control-Allow-Origin: * Set-Cookie: PHPSESSID=1f536f37ceb4082212a186e864925b55; path=/ Upgrade: h2 Connection: Upgrade, close Vary: Accept-Encoding Transfer-Encoding: chunked Content-Type: text/html; charset=utf-8
Open service 8.208.90.19:443 · www.wingwahromford.co.uk
2025-12-22 18:13
HTTP/1.1 200 OK Date: Mon, 22 Dec 2025 18:13:16 GMT Server: Apache Access-Control-Allow-Credentials: true Access-Control-Max-Age: 1800 Access-Control-Allow-Methods: GET, POST, PATCH, PUT, DELETE, OPTIONS Access-Control-Allow-Headers: Authorization, Content-Type, If-Match, If-Modified-Since, If-None-Match, If-Unmodified-Since, X-CSRF-TOKEN, X-Requested-With Access-Control-Allow-Origin: * Set-Cookie: PHPSESSID=1b0aa08375e88f16fe2eb82b745af579; path=/ Upgrade: h2 Connection: Upgrade, close Vary: Accept-Encoding Transfer-Encoding: chunked Content-Type: text/html; charset=utf-8
Open service 8.208.90.19:443 · www.wingwahromford.co.uk
2025-12-20 19:17
HTTP/1.1 200 OK Date: Sat, 20 Dec 2025 19:17:59 GMT Server: Apache Access-Control-Allow-Credentials: true Access-Control-Max-Age: 1800 Access-Control-Allow-Methods: GET, POST, PATCH, PUT, DELETE, OPTIONS Access-Control-Allow-Headers: Authorization, Content-Type, If-Match, If-Modified-Since, If-None-Match, If-Unmodified-Since, X-CSRF-TOKEN, X-Requested-With Access-Control-Allow-Origin: * Set-Cookie: PHPSESSID=e4ba16b3d9b0796e8e61c5f4f4c208aa; path=/ Upgrade: h2 Connection: Upgrade, close Vary: Accept-Encoding Transfer-Encoding: chunked Content-Type: text/html; charset=utf-8