Apache
tcp/443
GraphQL introspection is enabled.
This could leak to data leak if not properly configured.
Severity: medium
Fingerprint: c2db3a1c40d490db1a0bbaa350fb0c0078fc4ac48c86212e59bc7ecf641a8860
GraphQL introspection enabled at /graphql Types: 716 (by kind: ENUM: 37, INPUT_OBJECT: 78, INTERFACE: 3, OBJECT: 585, SCALAR: 10, UNION: 3) Operations: - Query: Query | fields: addresses, commonAnalyticsData, coverageChecks, deliverableAddresses, pwpolicy - Mutation: Mutation | fields: checkUidExistence, createAddress, createAddressV2, removeAddress, updateAddress Directives: apiSet, cacheControl, constraint, deprecated, forbidAnonymous, include, oneOf, requireToken, skip, specifiedBy (total: 10)
Severity: medium
Fingerprint: c2db3a1c40d490db1a0bbaa350fb0c0078fc4ac48c86212e59bc7ecf0afef587
GraphQL introspection enabled at /graphql Types: 716 (by kind: ENUM: 37, INPUT_OBJECT: 78, INTERFACE: 3, OBJECT: 585, SCALAR: 10, UNION: 3) Operations: - Query: Query | fields: addresses, commonAnalyticsData, coverageChecks, deliverableAddresses, pwpolicy - Mutation: Mutation | fields: checkUidExistence, createAddress, createAddressV2, removeAddress, updateAddress Directives: apiSet, cacheControl, constraint, deprecated, forbidAnonymous, include, oneOf, requireToken, skip, specifiedBy (total: 10) Detected: Magento
Severity: medium
Fingerprint: c2db3a1c40d490db1a0bbaa3edba241efabd150e70ee57fc1e248a293e029e6d
GraphQL introspection enabled at /graphql Types: 714 (by kind: ENUM: 37, INPUT_OBJECT: 78, INTERFACE: 3, OBJECT: 584, SCALAR: 10, UNION: 2) Operations: - Query: Query | fields: addresses, commonAnalyticsData, coverageChecks, deliverableAddresses, pwpolicy - Mutation: Mutation | fields: checkUidExistence, createAddress, createAddressV2, removeAddress, updateAddress Directives: apiSet, cacheControl, constraint, deprecated, forbidAnonymous, include, oneOf, requireToken, skip, specifiedBy (total: 10) Detected: Magento
Severity: medium
Fingerprint: c2db3a1c40d490db1a0bbaa3a02d8ad27efac022daa6a768cfd3a2d59208e0e1
GraphQL introspection enabled at /graphql Types: 688 (by kind: ENUM: 35, INPUT_OBJECT: 76, INTERFACE: 2, OBJECT: 564, SCALAR: 10, UNION: 1) Operations: - Query: Query | fields: addresses, commonAnalyticsData, coverageChecks, deliverableAddresses, pwpolicy - Mutation: Mutation | fields: checkUidExistence, createAddress, createAddressV2, removeAddress, updateAddress Directives: apiSet, cacheControl, constraint, deprecated, forbidAnonymous, include, oneOf, requireToken, skip, specifiedBy (total: 10) Detected: Magento
Severity: medium
Fingerprint: c2db3a1c40d490db1a0bbaa3de36c6f4930d69f87496e00a8809a41b7cab078b
GraphQL introspection enabled at /graphql Types: 681 (by kind: ENUM: 35, INPUT_OBJECT: 71, INTERFACE: 2, OBJECT: 562, SCALAR: 10, UNION: 1) Operations: - Query: Query | fields: addresses, commonAnalyticsData, coverageChecks, deliverableAddresses, pwpolicy - Mutation: Mutation | fields: checkUidExistence, createAddress, createAddressV2, removeAddress, updateAddress Directives: apiSet, cacheControl, constraint, deprecated, forbidAnonymous, include, oneOf, requireToken, skip, specifiedBy (total: 10) Detected: Magento
Severity: medium
Fingerprint: c2db3a1c40d490db1a0bbaa31cb556a17e0d6663c9640e0fe8638652099b61c1
GraphQL introspection enabled at /graphql Types: 669 (by kind: ENUM: 34, INPUT_OBJECT: 70, INTERFACE: 2, OBJECT: 552, SCALAR: 10, UNION: 1) Operations: - Query: Query | fields: addresses, commonAnalyticsData, coverageChecks, deliverableAddresses, pwpolicy - Mutation: Mutation | fields: checkUidExistence, createAddress, createAddressV2, removeAddress, updateAddress Directives: apiSet, cacheControl, constraint, deprecated, forbidAnonymous, include, oneOf, requireToken, skip, specifiedBy (total: 10)
Severity: medium
Fingerprint: c2db3a1c40d490db1a0bbaa32189598ad0d9783aeed6e66077276ced0adc43fa
GraphQL introspection enabled at /graphql Types: 657 (by kind: ENUM: 33, INPUT_OBJECT: 68, INTERFACE: 2, OBJECT: 543, SCALAR: 10, UNION: 1) Operations: - Query: Query | fields: addresses, commonAnalyticsData, coverageChecks, deliverableAddresses, pwpolicy - Mutation: Mutation | fields: checkUidExistence, createAddress, createAddressV2, removeAddress, updateAddress Directives: apiSet, cacheControl, constraint, deprecated, forbidAnonymous, include, oneOf, requireToken, skip, specifiedBy (total: 10)
Severity: medium
Fingerprint: c2db3a1c40d490db1a0bbaa329506ae754998fd5ac71f59d7b7c3fdcb38b6947
GraphQL introspection enabled at /graphql Types: 650 (by kind: ENUM: 33, INPUT_OBJECT: 68, INTERFACE: 2, OBJECT: 536, SCALAR: 10, UNION: 1) Operations: - Query: Query | fields: addresses, commonAnalyticsData, coverageChecks, deliverableAddresses, pwpolicy - Mutation: Mutation | fields: checkUidExistence, createAddress, createAddressV2, removeAddress, updateAddress Directives: apiSet, cacheControl, constraint, deprecated, forbidAnonymous, include, oneOf, requireToken, skip, specifiedBy (total: 10)
Open service 23.212.110.24:443 · mobile-api-uat.maxi.rs
2026-01-23 16:16
HTTP/1.1 200 OK Content-Type: text/html Content-Length: 32 Cache-Control: max-age=0 Date: Fri, 23 Jan 2026 16:16:49 GMT Connection: close Alt-Svc: h3=":443"; ma=93600 Vary: Accept-encoding, Origin X-DLH-Cache-Status: Constructed from child traceresponse: 00-42fb321c9d91d80527b96054634f0dde-cba4e50e59112c6c-00 X-Content-Type-Options: nosniff Content-Security-Policy: script-src 'unsafe-inline' 'unsafe-eval' https: blob:;object-src 'none' ;base-uri 'none'; upgrade-insecure-requests; frame-ancestors 'self'; Strict-Transport-Security: max-age=31536000; includeSubDomains Server: Apache Set-Cookie: _abck=F9836594999BB03F542228EF090FD768~-1~YAAQH27UFxprAdibAQAAsN2k6w+dVSd1QWDD+GEq7AbotQMvy9f3rGaQ0r2Zmg9N+Jwy6Mw9JK3Na+bbJ+yBZuAGy4WoH3m7zCflMhxGWbN+a5aeXFz40zL76tfA9XIXRc6dCpg+AJ4sdq8Huw671MMKSyD1j1+9DU+sYCuyO+YqojOT8Gt5NaxJv7AcDtBDYtHQMqKSxzhcd3F27s1Ie3oH3fnpaWGFs7RVhWv0Cl2GdhkkUuLw+2u+rNGuPmYui1e+yPfQUNOGsibPLj2UdPf42XBak8CHfn+6T5ASDVQBa/9+wgHq+Oks2YyF6HXdFHES9KfS71CY2A2QRGnFNsK3JRiATFaSChi05KZMcN5OpevdtAF47vk3/Mn939CX8RWwVlrzzSWIoP6DVE9/8OhHdxyJUe06sQdI1IbdVQ31lyFTCBN6txxaVPdBE28Mbp4=~-1~-1~-1~-1~-1; Domain=.maxi.rs; Path=/; Expires=Sat, 23 Jan 2027 16:16:49 GMT; Max-Age=31536000; Secure Set-Cookie: bm_sz=11B9861E4218CB9EBE77143D0734F895~YAAQH27UFxtrAdibAQAAsN2k6x4aNslWgkLkFm04DpU0Ayb+ANfgBc9clVH49sweTZNrSeqCGLmHB7NMPCwRrpcnK/ky8H2SmatpdhSQERNF4g5yo2VCaciG3xge7X6OJiADSxOG4Uhh8f84ZmymFTWeA0klGnE1hJRoygF43pjqz2OU+oduiJ0jAEa+AArejJEEuofhcOIwqiEsyG8gpwG0QZ5FDgJexdJ5Tukc29oZt8wZJ7nSu222AIZ+OqKOXL0IhMru348SuVfojurtX3SBdHPVE2gjbyQ6kLrDSiTWYVw286lK8uBcfXnvGE/GyGt4iTOvtLpbZ8nQZaFIWdRQQ4//sOj+wbI=~4600887~3553346; Domain=.maxi.rs; Path=/; Expires=Fri, 23 Jan 2026 20:16:49 GMT; Max-Age=14400 Welcome to Royal Ahold Delhaize.
Open service 23.212.110.24:443 · mobile-api-uat.maxi.rs
2026-01-09 14:01
HTTP/1.1 200 OK Content-Type: text/html Content-Length: 32 Cache-Control: max-age=0 Date: Fri, 09 Jan 2026 14:01:38 GMT Connection: close Alt-Svc: h3=":443"; ma=93600 Vary: Accept-encoding, Origin X-DLH-Cache-Status: Constructed from child traceresponse: 00-9fed503922d52ff2f9188dd36ae49251-2c574e2e30fbecd3-00 X-Content-Type-Options: nosniff Content-Security-Policy: script-src 'unsafe-inline' 'unsafe-eval' https: blob:;object-src 'none' ;base-uri 'none'; upgrade-insecure-requests; frame-ancestors 'self'; Strict-Transport-Security: max-age=31536000; includeSubDomains Server: Apache Set-Cookie: _abck=575CC1FC67B59C933A2CF649723E8FFF~-1~YAAQFG7UF/+dyCibAQAANxMQow9aXugZE0q+wOotOQtWVhPcA/ai/0NpH99VGQK56q3uBD/eh5fWA13pbe9cO9QnYF+Q6ZUO5Z75aDoLoZ/NUKqL+toOxxomhJv8j74Qb9tlzlMK5a0zVk5Euk40cp0Wcb6ipN9q29setfgI4UqJserGbuFlc05QNcxWwbpWKZpYrB59/IZ36oGBjccoG8AhwEInlYolWtWTzapul8bPMMZDBil8DCFdOhbyzSO+Cltb5aWOnggNx7FWCNq0tTN5Vgz2y5N6KShffzgMn/zhKPvsQ+QPuRC3/QRYOasCIir2imsjSQ+5MK5G3ooa4mKMuN5AeiYghkG59VtC+1tv5eItLWsSSK5j2nOxrI0XegdTq3kVsoQQGG+HsiK2lpjd1zpOjDF8u3FE/fXUcElGvRK4GfVyqYJdvXNs7cQG0nw=~-1~-1~-1~-1~-1; Domain=.maxi.rs; Path=/; Expires=Sat, 09 Jan 2027 14:01:38 GMT; Max-Age=31536000; Secure Set-Cookie: bm_sz=F503B6B266AD8D637FBCF748B3F81625~YAAQFG7UFwCeyCibAQAANxMQox6SeUekI5Us7mfF1q6o+HMqOSbsf2AXsXN1n3jJKDhaY+FHLBOz5UPmqNSRvLHv/27zV2Hpt6kC15i6s5WuiWD9Pb3biZvYs/bAoRoJLRTGphjtC1eNM/HqYYOx/QXp81P7OmxirlBgEO+aEk5lt7S64rjU9CqOySOGPaPnIH7AGLXKNoh7bePaMhDzwMvBqvBP1oSrKqiDsZvqtTPKGLyyjKEcCtDyGl2kVuDZQSAB6bOC4R7QYChx8+8gCU7kt95pL5mBhMzMH2ztti00gCv5NgRVII47/p2I6xxqE1v//Dd11K+4k9zSzPqHy4imXZnPzc4FaC9O~4535361~3752257; Domain=.maxi.rs; Path=/; Expires=Fri, 09 Jan 2026 18:01:38 GMT; Max-Age=14400 Welcome to Royal Ahold Delhaize.
Open service 23.212.110.24:443 · mobile-api-uat.maxi.rs
2025-12-22 16:05
HTTP/1.1 200 OK Content-Type: text/html Content-Length: 32 Cache-Control: max-age=0 Date: Mon, 22 Dec 2025 16:05:38 GMT Connection: close Alt-Svc: h3=":443"; ma=93600 Vary: Accept-encoding, Origin X-DLH-Cache-Status: Constructed from child traceresponse: 00-dea46fd12f0347a110c7420e0d1833f4-11c6487bfe4e8a87-00 X-Content-Type-Options: nosniff Content-Security-Policy: script-src 'unsafe-inline' 'unsafe-eval' https: blob:;object-src 'none' ;base-uri 'none'; upgrade-insecure-requests; frame-ancestors 'self'; Strict-Transport-Security: max-age=31536000; includeSubDomains Server: Apache Set-Cookie: _abck=A1685E213B8FC9B29DFCB23ED3F3F379~-1~YAAQFG7UF7hlwyabAQAA6CLPRg/Ok2E+cPnURIVuMotEkcu0YLGTSB3QQdaCr3GgjkBGNmbkvdRhzri/1E4somf25Ah4xaiB5AFCZMzvkB7wiwxXrbEQaMfrSIjtGr2cc0ydfZgRgiuONtHVo1hAq1ccAZ78757M6PvSBAyFNPFc/WAAVgyVfB33Q4D2x5SsObrjOH7VnHafrNjoFN0B8wugP7jNBFXPzEkUBnZGuB1hRwp14J7ibpTvabFXR/+O6uZC0FqPxKEBVTpKegmk3KJDN3ykQhz8e4neTHa9zSkBiXgBzvLii3Jad0MQtmpR9i9339oLFVktaM35l1QAhYQ7rOY70rlifc3b8iRkicTfIYWTvxCruROEnE6B58UKXjFm5Ybpj6idHp65igmxgjf2sMVSHCe6DFYaBSttO8lbm73+KGC36AyCZOwkoYFXKwo=~-1~-1~-1~-1~-1; Domain=.maxi.rs; Path=/; Expires=Tue, 22 Dec 2026 16:05:38 GMT; Max-Age=31536000; Secure Set-Cookie: bm_sz=7134B4FA81FC1D1C9DF4915807AA18EC~YAAQFG7UF7llwyabAQAA6CLPRh4fYpcUgt46Rqst3e5qNW/yp6El90o4713pnUFO7V2phU2UYCczIsFUT25Ma64/rpHMm5wXedzNFIZYkmVa18ljQgGSLdqtgF7jR3MFyKRa7oDj444swIg5jLGB89fxIF3XEjZn90p+1Ulw20EBqJV1v2cOFSWmtLr23u4AhAxOkmoUYx18dAI7FaaQ+JQ81rhFLHLDd/uiIFBnEBadmK079ycc2AgOeNNMn0gQLmxdGcLL2qGo1yWxjgvP2kQR5NzwefhVq9yxyjPSLaYjXCr4d3Gsz9KiSXRUp6mbiE/Gvqlp2ylaM+LOMBCx9g++4GEAJ+j61aFISA==~4277561~3293744; Domain=.maxi.rs; Path=/; Expires=Mon, 22 Dec 2025 20:05:38 GMT; Max-Age=14400 Welcome to Royal Ahold Delhaize.