Apache
tcp/443 tcp/80
The following URL (usually /.git/config
) is publicly accessible and is leaking source code and repository configuration.
Additionally the GIT credentials are present and could give unauthorized access to source code repository of private projects.
Severity: critical
Fingerprint: 2580fa947178c88602b1737db148c044b81b03713d63bb82370a65225a697939
[core] repositoryformatversion = 0 filemode = true bare = false logallrefupdates = true [remote "origin"] url = https://liquid-snow-tours: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@github.com/liquid-snow-tours/hakuba.git fetch = +refs/heads/*:refs/remotes/origin/*
Severity: critical
Fingerprint: 2580fa947178c88602b1737db148c044b81b03713d63bb82370a652231d3dab5
[core] repositoryformatversion = 0 filemode = true bare = false logallrefupdates = true [user] name = user email = user@example.com [revisr] token = AJ2PmKQGRPNZlOI0 current-remote = origin [remote "origin"] url = https://liquid-snow-tours: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@github.com/liquid-snow-tours/hakuba.git fetch = +refs/heads/*:refs/remotes/origin/*
Fingerprint: 2580fa947178c88602b1737db148c044b81b03713d63bb82370a6522be783345
[core] repositoryformatversion = 0 filemode = true bare = false logallrefupdates = true [user] name = user email = user@example.com [revisr] token = AJ2PmKQGRPNZlOI0 current-remote = origin [remote "origin"] url = https://wordpress-at-876648565844:VmPXjWQihaRNqyPKPRBv8Xq7p0U84YOJiPIzdeonQds=@git-codecommit.us-east-1.amazonaws.com/v1/repos/hakuba fetch = +refs/heads/*:refs/remotes/origin/*
Severity: critical
Fingerprint: 2580fa947e78dd08e645819d342d958cfde891ff6dab79eadb3ba03e078d0843
HTTP/1.1 200 OK Date: Sun, 07 May 2023 19:35:19 GMT Server: Apache X-Powered-By: PHP/7.4.13 X-Frame-Options: SAMEORIGIN Last-Modified: Tue, 04 Apr 2023 01:53:03 GMT Vary: Accept-Encoding Connection: close Transfer-Encoding: chunked Content-Type: text/html; charset=UTF-8 Page title: Hakuba.com | The Most Comprehensive Hakuba Resource[core] repositoryformatversion = 0 filemode = true bare = false logallrefupdates = true [user] name = user email = user@example.com [revisr] token = AJ2PmKQGRPNZlOI0 current-remote = origin [remote "origin"] url = https://wordpress-at-876648565844:VmPXjWQihaRNqyPKPRBv8Xq7p0U84YOJiPIzdeonQds=@git-codecommit.us-east-1.amazonaws.com/v1/repos/hakuba fetch = +refs/heads/*:refs/remotes/origin/*
The following URL (usually /.git/config
) is publicly accessible and is leaking source code and repository configuration.
Additionally the GIT credentials are present and could give unauthorized access to source code repository of private projects.
Severity: critical
Fingerprint: 2580fa947178c88602b1737db148c044b81b03713d63bb82370a65225a697939
[core] repositoryformatversion = 0 filemode = true bare = false logallrefupdates = true [remote "origin"] url = https://liquid-snow-tours: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@github.com/liquid-snow-tours/hakuba.git fetch = +refs/heads/*:refs/remotes/origin/*
Severity: critical
Fingerprint: 2580fa947178c88602b1737db148c044b81b03713d63bb82370a652231d3dab5
[core] repositoryformatversion = 0 filemode = true bare = false logallrefupdates = true [user] name = user email = user@example.com [revisr] token = AJ2PmKQGRPNZlOI0 current-remote = origin [remote "origin"] url = https://liquid-snow-tours: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@github.com/liquid-snow-tours/hakuba.git fetch = +refs/heads/*:refs/remotes/origin/*
Fingerprint: 2580fa947178c88602b1737db148c044b81b03713d63bb82370a6522be783345
[core] repositoryformatversion = 0 filemode = true bare = false logallrefupdates = true [user] name = user email = user@example.com [revisr] token = AJ2PmKQGRPNZlOI0 current-remote = origin [remote "origin"] url = https://wordpress-at-876648565844:VmPXjWQihaRNqyPKPRBv8Xq7p0U84YOJiPIzdeonQds=@git-codecommit.us-east-1.amazonaws.com/v1/repos/hakuba fetch = +refs/heads/*:refs/remotes/origin/*
No description available
Fingerprint: 33fc8a384ee3c2e738e1ea3738e1ea37009ef99b22f1e08844969c8844969c88
Nuclei scan report for tags wordpress, php: CVE-2017-5487 : WordPress Core < 4.7.1 - Username Enumeration by Manas_Harsh,daffainfo ------------- wp-includes/rest-api/endpoints/class-wp-rest-users-controller.php in the REST API implementation in WordPress 4.7 before 4.7.1 does not properly restrict listings of post authors, which allows remote attackers to obtain sensitive information via a wp-json/wp/v2/users request.
No description available
Fingerprint: 33fc8a384ee3c2e738e1ea3738e1ea37009ef99b22f1e08844969c8844969c88
Nuclei scan report for tags wordpress, php: CVE-2017-5487 : WordPress Core < 4.7.1 - Username Enumeration by Manas_Harsh,daffainfo ------------- wp-includes/rest-api/endpoints/class-wp-rest-users-controller.php in the REST API implementation in WordPress 4.7 before 4.7.1 does not properly restrict listings of post authors, which allows remote attackers to obtain sensitive information via a wp-json/wp/v2/users request.
Open service 35.74.11.136:443
2024-11-19 22:10
HTTP/1.1 200 OK Date: Tue, 19 Nov 2024 22:10:55 GMT Server: Apache cf-edge-cache: cache,platform=wordpress Link: <https://35.74.11.136/wp-json/>; rel="https://api.w.org/", <https://35.74.11.136/wp-json/wp/v2/pages/8>; rel="alternate"; title="JSON"; type="application/json", <https://35.74.11.136/>; rel=shortlink Vary: Accept-Encoding Connection: close Transfer-Encoding: chunked Content-Type: text/html; charset=UTF-8
Open service 35.74.11.136:443
2024-11-17 22:42
HTTP/1.1 200 OK Date: Sun, 17 Nov 2024 22:42:49 GMT Server: Apache cf-edge-cache: cache,platform=wordpress Link: <https://35.74.11.136/wp-json/>; rel="https://api.w.org/", <https://35.74.11.136/wp-json/wp/v2/pages/8>; rel="alternate"; title="JSON"; type="application/json", <https://35.74.11.136/>; rel=shortlink Vary: Accept-Encoding Connection: close Transfer-Encoding: chunked Content-Type: text/html; charset=UTF-8
Open service 35.74.11.136:443
2024-11-17 22:33
HTTP/1.1 200 OK Date: Sun, 17 Nov 2024 22:33:51 GMT Server: Apache cf-edge-cache: cache,platform=wordpress Link: <https://35.74.11.136/wp-json/>; rel="https://api.w.org/", <https://35.74.11.136/wp-json/wp/v2/pages/8>; rel="alternate"; title="JSON"; type="application/json", <https://35.74.11.136/>; rel=shortlink Vary: Accept-Encoding Connection: close Transfer-Encoding: chunked Content-Type: text/html; charset=UTF-8
Open service 35.74.11.136:80
2024-11-17 22:32
HTTP/1.1 200 OK Date: Sun, 17 Nov 2024 22:32:26 GMT Server: Apache cf-edge-cache: cache,platform=wordpress Link: <http://35.74.11.136/wp-json/>; rel="https://api.w.org/", <http://35.74.11.136/wp-json/wp/v2/pages/8>; rel="alternate"; title="JSON"; type="application/json", <http://35.74.11.136/>; rel=shortlink Vary: Accept-Encoding Connection: close Transfer-Encoding: chunked Content-Type: text/html; charset=UTF-8
Open service 35.74.11.136:80
2024-11-16 00:51
HTTP/1.1 200 OK Date: Sat, 16 Nov 2024 00:51:54 GMT Server: Apache cf-edge-cache: cache,platform=wordpress Link: <http://35.74.11.136/wp-json/>; rel="https://api.w.org/", <http://35.74.11.136/wp-json/wp/v2/pages/8>; rel="alternate"; title="JSON"; type="application/json", <http://35.74.11.136/>; rel=shortlink Vary: Accept-Encoding Connection: close Transfer-Encoding: chunked Content-Type: text/html; charset=UTF-8
Open service 35.74.11.136:443
2024-11-02 02:20
HTTP/1.1 200 OK Date: Sat, 02 Nov 2024 02:21:01 GMT Server: Apache cf-edge-cache: cache,platform=wordpress Link: <https://35.74.11.136/wp-json/>; rel="https://api.w.org/", <https://35.74.11.136/wp-json/wp/v2/pages/8>; rel="alternate"; title="JSON"; type="application/json", <https://35.74.11.136/>; rel=shortlink Vary: Accept-Encoding Connection: close Transfer-Encoding: chunked Content-Type: text/html; charset=UTF-8
Open service 35.74.11.136:80
2024-11-02 01:51
HTTP/1.1 200 OK Date: Sat, 02 Nov 2024 01:51:04 GMT Server: Apache cf-edge-cache: cache,platform=wordpress Link: <http://35.74.11.136/wp-json/>; rel="https://api.w.org/", <http://35.74.11.136/wp-json/wp/v2/pages/8>; rel="alternate"; title="JSON"; type="application/json", <http://35.74.11.136/>; rel=shortlink Vary: Accept-Encoding Connection: close Transfer-Encoding: chunked Content-Type: text/html; charset=UTF-8
Open service 35.74.11.136:443
2024-11-01 21:12
HTTP/1.1 200 OK Date: Fri, 01 Nov 2024 21:12:22 GMT Server: Apache cf-edge-cache: cache,platform=wordpress Link: <https://35.74.11.136/wp-json/>; rel="https://api.w.org/", <https://35.74.11.136/wp-json/wp/v2/pages/8>; rel="alternate"; title="JSON"; type="application/json", <https://35.74.11.136/>; rel=shortlink Vary: Accept-Encoding Connection: close Transfer-Encoding: chunked Content-Type: text/html; charset=UTF-8
Open service 35.74.11.136:80
2024-10-31 23:37
HTTP/1.1 200 OK Date: Thu, 31 Oct 2024 23:37:42 GMT Server: Apache cf-edge-cache: cache,platform=wordpress Link: <http://35.74.11.136/wp-json/>; rel="https://api.w.org/", <http://35.74.11.136/wp-json/wp/v2/pages/8>; rel="alternate"; title="JSON"; type="application/json", <http://35.74.11.136/>; rel=shortlink Vary: Accept-Encoding Connection: close Transfer-Encoding: chunked Content-Type: text/html; charset=UTF-8
Open service 35.74.11.136:80
2024-10-30 01:23
HTTP/1.1 200 OK Date: Wed, 30 Oct 2024 01:23:08 GMT Server: Apache cf-edge-cache: cache,platform=wordpress Link: <http://35.74.11.136/wp-json/>; rel="https://api.w.org/", <http://35.74.11.136/wp-json/wp/v2/pages/8>; rel="alternate"; title="JSON"; type="application/json", <http://35.74.11.136/>; rel=shortlink Vary: Accept-Encoding Connection: close Transfer-Encoding: chunked Content-Type: text/html; charset=UTF-8
Open service 35.74.11.136:443
2024-10-30 01:05
HTTP/1.1 200 OK Date: Wed, 30 Oct 2024 01:06:04 GMT Server: Apache cf-edge-cache: cache,platform=wordpress Link: <https://35.74.11.136/wp-json/>; rel="https://api.w.org/", <https://35.74.11.136/wp-json/wp/v2/pages/8>; rel="alternate"; title="JSON"; type="application/json", <https://35.74.11.136/>; rel=shortlink Vary: Accept-Encoding Connection: close Transfer-Encoding: chunked Content-Type: text/html; charset=UTF-8
Open service 35.74.11.136:443
2024-10-30 00:15
HTTP/1.1 200 OK Date: Wed, 30 Oct 2024 00:15:23 GMT Server: Apache cf-edge-cache: cache,platform=wordpress Link: <https://35.74.11.136/wp-json/>; rel="https://api.w.org/", <https://35.74.11.136/wp-json/wp/v2/pages/8>; rel="alternate"; title="JSON"; type="application/json", <https://35.74.11.136/>; rel=shortlink Vary: Accept-Encoding Connection: close Transfer-Encoding: chunked Content-Type: text/html; charset=UTF-8
Open service 35.74.11.136:80
2024-10-29 23:04
HTTP/1.1 200 OK Date: Tue, 29 Oct 2024 23:04:25 GMT Server: Apache cf-edge-cache: cache,platform=wordpress Link: <http://35.74.11.136/wp-json/>; rel="https://api.w.org/", <http://35.74.11.136/wp-json/wp/v2/pages/8>; rel="alternate"; title="JSON"; type="application/json", <http://35.74.11.136/>; rel=shortlink Vary: Accept-Encoding Connection: close Transfer-Encoding: chunked Content-Type: text/html; charset=UTF-8
Open service 35.74.11.136:443
2024-10-21 23:37
HTTP/1.1 200 OK Date: Mon, 21 Oct 2024 23:37:07 GMT Server: Apache cf-edge-cache: cache,platform=wordpress Link: <https://35.74.11.136/wp-json/>; rel="https://api.w.org/", <https://35.74.11.136/wp-json/wp/v2/pages/8>; rel="alternate"; title="JSON"; type="application/json", <https://35.74.11.136/>; rel=shortlink Vary: Accept-Encoding Connection: close Transfer-Encoding: chunked Content-Type: text/html; charset=UTF-8
Open service 35.74.11.136:80
2024-10-21 23:24
HTTP/1.1 200 OK Date: Mon, 21 Oct 2024 23:24:53 GMT Server: Apache cf-edge-cache: cache,platform=wordpress Link: <http://35.74.11.136/wp-json/>; rel="https://api.w.org/", <http://35.74.11.136/wp-json/wp/v2/pages/8>; rel="alternate"; title="JSON"; type="application/json", <http://35.74.11.136/>; rel=shortlink Vary: Accept-Encoding Connection: close Transfer-Encoding: chunked Content-Type: text/html; charset=UTF-8
Open service 35.74.11.136:443
2024-10-19 23:50
HTTP/1.1 200 OK Date: Sat, 19 Oct 2024 23:50:12 GMT Server: Apache cf-edge-cache: cache,platform=wordpress Link: <https://35.74.11.136/wp-json/>; rel="https://api.w.org/", <https://35.74.11.136/wp-json/wp/v2/pages/8>; rel="alternate"; title="JSON"; type="application/json", <https://35.74.11.136/>; rel=shortlink Vary: Accept-Encoding Connection: close Transfer-Encoding: chunked Content-Type: text/html; charset=UTF-8
Open service 35.74.11.136:80
2024-10-19 23:21
HTTP/1.1 200 OK Date: Sat, 19 Oct 2024 23:21:49 GMT Server: Apache cf-edge-cache: cache,platform=wordpress Link: <http://35.74.11.136/wp-json/>; rel="https://api.w.org/", <http://35.74.11.136/wp-json/wp/v2/pages/8>; rel="alternate"; title="JSON"; type="application/json", <http://35.74.11.136/>; rel=shortlink Vary: Accept-Encoding Connection: close Transfer-Encoding: chunked Content-Type: text/html; charset=UTF-8
Open service 35.74.11.136:443
2024-10-19 23:05
HTTP/1.1 200 OK Date: Sat, 19 Oct 2024 23:05:59 GMT Server: Apache cf-edge-cache: cache,platform=wordpress Link: <https://35.74.11.136/wp-json/>; rel="https://api.w.org/", <https://35.74.11.136/wp-json/wp/v2/pages/8>; rel="alternate"; title="JSON"; type="application/json", <https://35.74.11.136/>; rel=shortlink Vary: Accept-Encoding Connection: close Transfer-Encoding: chunked Content-Type: text/html; charset=UTF-8
Open service 35.74.11.136:80
2024-10-17 23:51
HTTP/1.1 200 OK Date: Thu, 17 Oct 2024 23:51:26 GMT Server: Apache cf-edge-cache: cache,platform=wordpress Link: <http://35.74.11.136/wp-json/>; rel="https://api.w.org/", <http://35.74.11.136/wp-json/wp/v2/pages/8>; rel="alternate"; title="JSON"; type="application/json", <http://35.74.11.136/>; rel=shortlink Vary: Accept-Encoding Connection: close Transfer-Encoding: chunked Content-Type: text/html; charset=UTF-8
Open service 35.74.11.136:443
2024-10-17 23:36
HTTP/1.1 200 OK Date: Thu, 17 Oct 2024 23:36:28 GMT Server: Apache cf-edge-cache: cache,platform=wordpress Link: <https://35.74.11.136/wp-json/>; rel="https://api.w.org/", <https://35.74.11.136/wp-json/wp/v2/pages/8>; rel="alternate"; title="JSON"; type="application/json", <https://35.74.11.136/>; rel=shortlink Vary: Accept-Encoding Connection: close Transfer-Encoding: chunked Content-Type: text/html; charset=UTF-8
Open service 35.74.11.136:443
2024-10-17 23:07
HTTP/1.1 200 OK Date: Thu, 17 Oct 2024 23:07:46 GMT Server: Apache cf-edge-cache: cache,platform=wordpress Link: <https://35.74.11.136/wp-json/>; rel="https://api.w.org/", <https://35.74.11.136/wp-json/wp/v2/pages/8>; rel="alternate"; title="JSON"; type="application/json", <https://35.74.11.136/>; rel=shortlink Vary: Accept-Encoding Connection: close Transfer-Encoding: chunked Content-Type: text/html; charset=UTF-8