Date of the scan: Thu, 25 Sep 2025 11:49:23 +0000. Scope of the scan: folder. Crawled pages: 413
| Category | Number of vulnerabilities found |
|---|---|
| Backup file | 0 |
| Cleartext Submission of Password | 0 |
| Weak credentials | 0 |
| CRLF Injection | 0 |
| Content Security Policy Configuration | 1 |
| Cross Site Request Forgery | 0 |
| Potentially dangerous file | 0 |
| Command execution | 0 |
| Path Traversal | 0 |
| Fingerprint web application framework | 0 |
| Fingerprint web server | 0 |
| Htaccess Bypass | 0 |
| HTML Injection | 0 |
| Clickjacking Protection | 1 |
| HTTP Strict Transport Security (HSTS) | 1 |
| MIME Type Confusion | 1 |
| HttpOnly Flag cookie | 1 |
| Unencrypted Channels | 0 |
| Inconsistent Redirection | 0 |
| Information Disclosure - Full Path | 0 |
| LDAP Injection | 0 |
| Log4Shell | 0 |
| Open Redirect | 0 |
| Reflected Cross Site Scripting | 0 |
| Secure Flag cookie | 1 |
| Spring4Shell | 0 |
| SQL Injection | 0 |
| TLS/SSL misconfigurations | 0 |
| Server Side Request Forgery | 0 |
| Stored HTML Injection | 0 |
| Stored Cross Site Scripting | 0 |
| Subdomain takeover | 0 |
| Blind SQL Injection | 0 |
| Unrestricted File Upload | 0 |
| Vulnerable software | 0 |
| Internal Server Error | 0 |
| Resource consumption | 0 |
| Review Webserver Metafiles for Information Leakage | 0 |
| Fingerprint web technology | 0 |
| HTTP Methods | 0 |
| TLS/SSL misconfigurations | 0 |
CSP is not set for URL: https://dev.a1mc.ru/
GET / HTTP/1.1
host: dev.a1mc.ru
connection: keep-alive
user-agent: Mozilla/5.0 (Windows NT 6.1; rv:45.0) Gecko/20100101 Firefox/45.0
accept-language: en-US
accept-encoding: gzip, deflate, br
accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/webp,*/*;q=0.8
curl "https://dev.a1mc.ru/"
['WSTG-CONF-12', 'OSHP-Content-Security-Policy']
X-Frame-Options is not set
GET / HTTP/1.1
host: dev.a1mc.ru
connection: keep-alive
user-agent: Mozilla/5.0 (Windows NT 6.1; rv:45.0) Gecko/20100101 Firefox/45.0
accept-language: en-US
accept-encoding: gzip, deflate, br
accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/webp,*/*;q=0.8
curl "https://dev.a1mc.ru/"
['OSHP-X-Frame-Options']
Strict-Transport-Security is not set
GET / HTTP/1.1
host: dev.a1mc.ru
connection: keep-alive
user-agent: Mozilla/5.0 (Windows NT 6.1; rv:45.0) Gecko/20100101 Firefox/45.0
accept-language: en-US
accept-encoding: gzip, deflate, br
accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/webp,*/*;q=0.8
curl "https://dev.a1mc.ru/"
['WSTG-CONF-07', 'OSHP-HTTP-Strict-Transport-Security']
X-Content-Type-Options is not set
GET /konohamod/ HTTP/1.1
host: dev.a1mc.ru
connection: keep-alive
user-agent: Mozilla/5.0 (Windows NT 6.1; rv:45.0) Gecko/20100101 Firefox/45.0
accept-language: en-US
accept-encoding: gzip, deflate, br
accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/webp,*/*;q=0.8
curl "https://dev.a1mc.ru/konohamod/"
['OSHP-X-Content-Type-Options']
HttpOnly flag is not set on the cookie 'PHPSESSID' set at 'https://dev.a1mc.ru/photo/'
GET /photo/ HTTP/1.1
host: dev.a1mc.ru
connection: keep-alive
user-agent: Mozilla/5.0 (Windows NT 6.1; rv:45.0) Gecko/20100101 Firefox/45.0
accept-language: en-US
accept-encoding: gzip, deflate, br
accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/webp,*/*;q=0.8
curl "https://dev.a1mc.ru/photo/"
['WSTG-SESS-02']
Secure flag is not set on the cookie: 'PHPSESSID' set at 'https://dev.a1mc.ru/photo/'
GET /photo/ HTTP/1.1
host: dev.a1mc.ru
connection: keep-alive
user-agent: Mozilla/5.0 (Windows NT 6.1; rv:45.0) Gecko/20100101 Firefox/45.0
accept-language: en-US
accept-encoding: gzip, deflate, br
accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/webp,*/*;q=0.8
curl "https://dev.a1mc.ru/photo/"
['WSTG-SESS-02']