- Nikto v2.6.0
---------------------------------------------------------------------------
+ Target IP: 13.248.137.138
+ Target Hostname: www.competiscan.com
+ Target Port: 80
+ Platform: Unknown
+ Start Time: 2026-08-14 06:50:24 (GMT-4)
---------------------------------------------------------------------------
+ Server: Apache/2.4.61 (Amazon) PHP/5.6.40
+ Multiple IPs found: 13.248.137.138, 76.223.12.112
+ [999986] /: Retrieved x-powered-by header: PHP/5.6.40.
+ [750500] /icons/: Directory indexing found.
+ [999962] /: Server banner changed from 'Apache/2.4.61 (Amazon) PHP/5.6.40' to 'awselb/2.0'.
+ [013587] /: Suggested security header missing: x-content-type-options. See: https://developer.mozilla.org/en-US/docs/Web/HTTP/Headers/X-Content-Type-Options
+ [013587] /: Suggested security header missing: strict-transport-security. See: https://developer.mozilla.org/en-US/docs/Web/HTTP/Headers/Strict-Transport-Security
+ [013587] /: Suggested security header missing: referrer-policy. See: https://developer.mozilla.org/en-US/docs/Web/HTTP/Headers/Referrer-Policy
+ [013587] /: Suggested security header missing: permissions-policy. See: https://developer.mozilla.org/en-US/docs/Web/HTTP/Headers/Permissions-Policy
+ [95] /: Cookie PHPSESSID created without the httponly flag. See: https://developer.mozilla.org/en-US/docs/Web/HTTP/Cookies
+ [600050] Apache/2.4.61 appears to be outdated (current is at least 2.4.66).
+ [600625] PHP/5.6.40 appears to be outdated (current is at least 8.5.1).
+ [800262] /: PHP/5.6 - PHP 3/4/5 and 7.0 are End of Life products without support.
+ [000427] /: Link header(s) found with value(s): ; rel="https://api.w.org/",; rel=shortlink. See: https://developer.mozilla.org/en-US/docs/Web/HTTP/Headers/Link
+ [999967] /: Web Server returns a valid response with junk HTTP methods which may cause false positives.
+ [999972] /: DEBUG HTTP verb may show server debugging information. See: https://docs.microsoft.com/en-us/visualstudio/debugger/how-to-enable-debugging-for-aspnet-applications?view=vs-2017
+ [000777] /user.php?op=confirmnewuser&module=NS-NewUser&uNikto=%22%3E%3Cimg%20src=%22javascript:alert(document.cookie);%22%3E&email=test@test.com: Post Nuke 0.7.2.3-Phoenix is vulnerable to Cross Site Scripting (XSS).
+ Scan terminated: 0 errors and 15 items reported on the remote host
+ End Time: 2026-08-14 06:51:25 (GMT-4) (61 seconds)
---------------------------------------------------------------------------
+ 1 host(s) tested