Date of the scan: Thu, 25 Sep 2025 11:49:23 +0000. Scope of the scan: folder. Crawled pages: 413
| Category | Number of vulnerabilities found | 
|---|---|
| Backup file | 0 | 
| Cleartext Submission of Password | 0 | 
| Weak credentials | 0 | 
| CRLF Injection | 0 | 
| Content Security Policy Configuration | 1 | 
| Cross Site Request Forgery | 0 | 
| Potentially dangerous file | 0 | 
| Command execution | 0 | 
| Path Traversal | 0 | 
| Fingerprint web application framework | 0 | 
| Fingerprint web server | 0 | 
| Htaccess Bypass | 0 | 
| HTML Injection | 0 | 
| Clickjacking Protection | 1 | 
| HTTP Strict Transport Security (HSTS) | 1 | 
| MIME Type Confusion | 1 | 
| HttpOnly Flag cookie | 1 | 
| Unencrypted Channels | 0 | 
| Inconsistent Redirection | 0 | 
| Information Disclosure - Full Path | 0 | 
| LDAP Injection | 0 | 
| Log4Shell | 0 | 
| Open Redirect | 0 | 
| Reflected Cross Site Scripting | 0 | 
| Secure Flag cookie | 1 | 
| Spring4Shell | 0 | 
| SQL Injection | 0 | 
| TLS/SSL misconfigurations | 0 | 
| Server Side Request Forgery | 0 | 
| Stored HTML Injection | 0 | 
| Stored Cross Site Scripting | 0 | 
| Subdomain takeover | 0 | 
| Blind SQL Injection | 0 | 
| Unrestricted File Upload | 0 | 
| Vulnerable software | 0 | 
| Internal Server Error | 0 | 
| Resource consumption | 0 | 
| Review Webserver Metafiles for Information Leakage | 0 | 
| Fingerprint web technology | 0 | 
| HTTP Methods | 0 | 
| TLS/SSL misconfigurations | 0 | 
CSP is not set for URL: https://dev.a1mc.ru/
                                    GET / HTTP/1.1
                                    
                                    host: dev.a1mc.ru
                                    
                                    connection: keep-alive
                                    
                                    user-agent: Mozilla/5.0 (Windows NT 6.1; rv:45.0) Gecko/20100101 Firefox/45.0
                                    
                                    accept-language: en-US
                                    
                                    accept-encoding: gzip, deflate, br
                                    
                                    accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/webp,*/*;q=0.8
                                    
                            
                        curl "https://dev.a1mc.ru/"
['WSTG-CONF-12', 'OSHP-Content-Security-Policy']
X-Frame-Options is not set
                                    GET / HTTP/1.1
                                    
                                    host: dev.a1mc.ru
                                    
                                    connection: keep-alive
                                    
                                    user-agent: Mozilla/5.0 (Windows NT 6.1; rv:45.0) Gecko/20100101 Firefox/45.0
                                    
                                    accept-language: en-US
                                    
                                    accept-encoding: gzip, deflate, br
                                    
                                    accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/webp,*/*;q=0.8
                                    
                            
                        curl "https://dev.a1mc.ru/"
['OSHP-X-Frame-Options']
Strict-Transport-Security is not set
                                    GET / HTTP/1.1
                                    
                                    host: dev.a1mc.ru
                                    
                                    connection: keep-alive
                                    
                                    user-agent: Mozilla/5.0 (Windows NT 6.1; rv:45.0) Gecko/20100101 Firefox/45.0
                                    
                                    accept-language: en-US
                                    
                                    accept-encoding: gzip, deflate, br
                                    
                                    accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/webp,*/*;q=0.8
                                    
                            
                        curl "https://dev.a1mc.ru/"
['WSTG-CONF-07', 'OSHP-HTTP-Strict-Transport-Security']
X-Content-Type-Options is not set
                                    GET /konohamod/ HTTP/1.1
                                    
                                    host: dev.a1mc.ru
                                    
                                    connection: keep-alive
                                    
                                    user-agent: Mozilla/5.0 (Windows NT 6.1; rv:45.0) Gecko/20100101 Firefox/45.0
                                    
                                    accept-language: en-US
                                    
                                    accept-encoding: gzip, deflate, br
                                    
                                    accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/webp,*/*;q=0.8
                                    
                            
                        curl "https://dev.a1mc.ru/konohamod/"
['OSHP-X-Content-Type-Options']
HttpOnly flag is not set on the cookie 'PHPSESSID' set at 'https://dev.a1mc.ru/photo/'
                                    GET /photo/ HTTP/1.1
                                    
                                    host: dev.a1mc.ru
                                    
                                    connection: keep-alive
                                    
                                    user-agent: Mozilla/5.0 (Windows NT 6.1; rv:45.0) Gecko/20100101 Firefox/45.0
                                    
                                    accept-language: en-US
                                    
                                    accept-encoding: gzip, deflate, br
                                    
                                    accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/webp,*/*;q=0.8
                                    
                            
                        curl "https://dev.a1mc.ru/photo/"
['WSTG-SESS-02']
Secure flag is not set on the cookie: 'PHPSESSID' set at 'https://dev.a1mc.ru/photo/'
                                    GET /photo/ HTTP/1.1
                                    
                                    host: dev.a1mc.ru
                                    
                                    connection: keep-alive
                                    
                                    user-agent: Mozilla/5.0 (Windows NT 6.1; rv:45.0) Gecko/20100101 Firefox/45.0
                                    
                                    accept-language: en-US
                                    
                                    accept-encoding: gzip, deflate, br
                                    
                                    accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/webp,*/*;q=0.8
                                    
                            
                        curl "https://dev.a1mc.ru/photo/"
['WSTG-SESS-02']