Date of the scan: Thu, 25 Sep 2025 11:49:23 +0000. Scope of the scan: folder. Crawled pages: 413
Category | Number of vulnerabilities found |
---|---|
Backup file | 0 |
Cleartext Submission of Password | 0 |
Weak credentials | 0 |
CRLF Injection | 0 |
Content Security Policy Configuration | 1 |
Cross Site Request Forgery | 0 |
Potentially dangerous file | 0 |
Command execution | 0 |
Path Traversal | 0 |
Fingerprint web application framework | 0 |
Fingerprint web server | 0 |
Htaccess Bypass | 0 |
HTML Injection | 0 |
Clickjacking Protection | 1 |
HTTP Strict Transport Security (HSTS) | 1 |
MIME Type Confusion | 1 |
HttpOnly Flag cookie | 1 |
Unencrypted Channels | 0 |
Inconsistent Redirection | 0 |
Information Disclosure - Full Path | 0 |
LDAP Injection | 0 |
Log4Shell | 0 |
Open Redirect | 0 |
Reflected Cross Site Scripting | 0 |
Secure Flag cookie | 1 |
Spring4Shell | 0 |
SQL Injection | 0 |
TLS/SSL misconfigurations | 0 |
Server Side Request Forgery | 0 |
Stored HTML Injection | 0 |
Stored Cross Site Scripting | 0 |
Subdomain takeover | 0 |
Blind SQL Injection | 0 |
Unrestricted File Upload | 0 |
Vulnerable software | 0 |
Internal Server Error | 0 |
Resource consumption | 0 |
Review Webserver Metafiles for Information Leakage | 0 |
Fingerprint web technology | 0 |
HTTP Methods | 0 |
TLS/SSL misconfigurations | 0 |
CSP is not set for URL: https://dev.a1mc.ru/
GET / HTTP/1.1
host: dev.a1mc.ru
connection: keep-alive
user-agent: Mozilla/5.0 (Windows NT 6.1; rv:45.0) Gecko/20100101 Firefox/45.0
accept-language: en-US
accept-encoding: gzip, deflate, br
accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/webp,*/*;q=0.8
curl "https://dev.a1mc.ru/"
['WSTG-CONF-12', 'OSHP-Content-Security-Policy']
X-Frame-Options is not set
GET / HTTP/1.1
host: dev.a1mc.ru
connection: keep-alive
user-agent: Mozilla/5.0 (Windows NT 6.1; rv:45.0) Gecko/20100101 Firefox/45.0
accept-language: en-US
accept-encoding: gzip, deflate, br
accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/webp,*/*;q=0.8
curl "https://dev.a1mc.ru/"
['OSHP-X-Frame-Options']
Strict-Transport-Security is not set
GET / HTTP/1.1
host: dev.a1mc.ru
connection: keep-alive
user-agent: Mozilla/5.0 (Windows NT 6.1; rv:45.0) Gecko/20100101 Firefox/45.0
accept-language: en-US
accept-encoding: gzip, deflate, br
accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/webp,*/*;q=0.8
curl "https://dev.a1mc.ru/"
['WSTG-CONF-07', 'OSHP-HTTP-Strict-Transport-Security']
X-Content-Type-Options is not set
GET /konohamod/ HTTP/1.1
host: dev.a1mc.ru
connection: keep-alive
user-agent: Mozilla/5.0 (Windows NT 6.1; rv:45.0) Gecko/20100101 Firefox/45.0
accept-language: en-US
accept-encoding: gzip, deflate, br
accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/webp,*/*;q=0.8
curl "https://dev.a1mc.ru/konohamod/"
['OSHP-X-Content-Type-Options']
HttpOnly flag is not set on the cookie 'PHPSESSID' set at 'https://dev.a1mc.ru/photo/'
GET /photo/ HTTP/1.1
host: dev.a1mc.ru
connection: keep-alive
user-agent: Mozilla/5.0 (Windows NT 6.1; rv:45.0) Gecko/20100101 Firefox/45.0
accept-language: en-US
accept-encoding: gzip, deflate, br
accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/webp,*/*;q=0.8
curl "https://dev.a1mc.ru/photo/"
['WSTG-SESS-02']
Secure flag is not set on the cookie: 'PHPSESSID' set at 'https://dev.a1mc.ru/photo/'
GET /photo/ HTTP/1.1
host: dev.a1mc.ru
connection: keep-alive
user-agent: Mozilla/5.0 (Windows NT 6.1; rv:45.0) Gecko/20100101 Firefox/45.0
accept-language: en-US
accept-encoding: gzip, deflate, br
accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/webp,*/*;q=0.8
curl "https://dev.a1mc.ru/photo/"
['WSTG-SESS-02']