- Nikto v2.6.0
---------------------------------------------------------------------------
+ Your Nikto installation is out of date.
+ Target IP: 75.2.60.5
+ Target Hostname: sd2industries.com
+ Target Port: 80
+ Platform: Unknown
+ Start Time: 2026-04-19 22:58:41 (GMT-4)
---------------------------------------------------------------------------
+ Server: Netlify
+ No CGI Directories found (use '-C all' to force check all possible dirs). CGI tests skipped.
+ [013587] /: Suggested security header missing: strict-transport-security. See: https://developer.mozilla.org/en-US/docs/Web/HTTP/Headers/Strict-Transport-Security
+ [013587] /: Suggested security header missing: x-content-type-options. See: https://developer.mozilla.org/en-US/docs/Web/HTTP/Headers/X-Content-Type-Options
+ [013587] /: Suggested security header missing: referrer-policy. See: https://developer.mozilla.org/en-US/docs/Web/HTTP/Headers/Referrer-Policy
+ [013587] /: Suggested security header missing: content-security-policy. See: https://developer.mozilla.org/en-US/docs/Web/HTTP/CSP
+ [013587] /: Suggested security header missing: permissions-policy. See: https://developer.mozilla.org/en-US/docs/Web/HTTP/Headers/Permissions-Policy
+ [000702] /themes/mambosimple.php?detection=detected&sitename=: Mambo PHP Portal/Server is vulnerable to Cross Site Scripting (XSS). See: https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2003-1204
+ [000703] /index.php?option=search&searchword=: Mambo Site Server 4.0 build 10 is vulnerable to Cross Site Scripting (XSS).
+ [000704] /emailfriend/emailnews.php?id=\": Mambo PHP Portal/Server is vulnerable to Cross Site Scripting (XSS). See: https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2003-1204
+ [000705] /emailfriend/emailfaq.php?id=\": Mambo PHP Portal/Server is vulnerable to Cross Site Scripting (XSS). See: https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2003-1204
+ [000706] /emailfriend/emailarticle.php?id=\": Mambo PHP Portal/Server is vulnerable to Cross Site Scripting (XSS). See: https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2003-1204
+ [000707] /administrator/upload.php?newbanner=1&choice=\": Mambo PHP Portal/Server is vulnerable to Cross Site Scripting (XSS).
+ [000708] /administrator/popups/sectionswindow.php?type=web&link=\": Mambo PHP Portal/Server is vulnerable to Cross Site Scripting (XSS). See: https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2003-1204
+ [000709] /administrator/gallery/view.php?path=\": Mambo PHP Portal/Server is vulnerable to Cross Site Scripting (XSS). See: https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2003-1204
+ [000710] /administrator/gallery/uploadimage.php?directory=\": Mambo PHP Portal/Server is vulnerable to Cross Site Scripting (XSS). See: https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2003-1204
+ [000711] /administrator/gallery/navigation.php?directory=\": Mambo PHP Portal/Server is vulnerable to Cross Site Scripting (XSS). See: https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2003-1204
+ [000712] /administrator/gallery/gallery.php?directory=\": Mambo PHP Portal/Server is vulnerable to Cross Site Scripting (XSS). See: https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2003-1204
+ [000714] /https-admserv/bin/index?/: Sun ONE Web Server 6.1 administration control is vulnerable to XSS attacks.
+ [000715] /clusterframe.jsp?cluster=: Macromedia JRun 4.x JMC Interface, clusterframe.jsp file is vulnerable to a XSS attack.
+ [000717] /upload.php?type=\": Mambo PHP Portal/Server is vulnerable to Cross Site Scripting (XSS).
+ [000718] /soinfo.php?\">: The PHP script soinfo.php is vulnerable to Cross Site Scripting. Set expose_php = Off in php.ini. See: https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2002-1954
+ [000725] /servlet/MsgPage?action=test&msg=: NetDetector 3.0 and below are vulnerable to Cross Site Scripting (XSS).
+ [000730] /servlets/MsgPage?action=badlogin&msg=: The NetDetector install is vulnerable to Cross Site Scripting (XSS) in its invalid login message.
+ [000734] /SiteServer/Knowledge/Default.asp?ctr=\">: Site Server is vulnerable to Cross Site Scripting.
+ [000735] /_mem_bin/formslogin.asp?\">: Site Server is vulnerable to Cross Site Scripting.
+ [000741] /webcalendar/week.php?eventinfo=: Webcalendar 0.9.42 and below are vulnerable to Cross Site Scripting (XSS).
+ [000776] /user.php?op=userinfo&uname=: The PHP-Nuke installation is vulnerable to Cross Site Scripting (XSS). Update to versions above 5.3.1.
+ [000777] /user.php?op=confirmnewuser&module=NS-NewUser&uNikto=%22%3E%3Cimg%20src=%22javascript:alert(document.cookie);%22%3E&email=test@test.com: Post Nuke 0.7.2.3-Phoenix is vulnerable to Cross Site Scripting (XSS).
+ [000780] /templates/form_header.php?noticemsg=: MyMarket 1.71 is vulnerable to Cross Site Scripting (XSS).
+ [000782] /supporter/index.php?t=updateticketlog&id=<script></script>: MyHelpdesk versions v20020509 and older are vulnerable to Cross Site Scripting (XSS). See: https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2002-0931
+ [000783] /supporter/index.php?t=tickettime&id=<script></script>: MyHelpdesk versions v20020509 and older are vulnerable to Cross Site Scripting (XSS). See: https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2002-0931
+ [000784] /supporter/index.php?t=ticketfiles&id=<script></script>: MyHelpdesk versions v20020509 and older are vulnerable to Cross Site Scripting (XSS). See: https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2002-0931
+ [000785] /sunshop.index.php?action=storenew&username=: SunShop is vulnerable to Cross Site Scripting (XSS) in the signup page.
+ [000786] /submit.php?subject=&story=&storyext=&op=Preview: This install of PHP-Nuke is vulnerable to Cross Site Scripting (XSS). See: https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2001-1524
+ [000787] /ss000007.pl?PRODREF=: Actinic E-Commerce services is vulnerable to Cross Site Scripting (XSS). See: https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2002-1732
+ [000790] /setup.exe?&page=list_users&user=P: CiscoSecure ACS v3.0(1) Build 40 allows Cross Site Scripting (XSS). See: https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2002-0938
+ [000793] /servlet/ContentServer?pagename=: Open Market Inc. ContentServer is vulnerable to Cross Site Scripting (XSS) in the login-error page.
+ [000797] /search.php?searchstring=: Gallery 1.3.4 and below is vulnerable to Cross Site Scripting (XSS). Upgrade to the latest version. See: https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2003-0614
+ [000798] /search.php?searchfor=\">: Siteframe 2.2.4 is vulnerable to Cross Site Scripting (XSS). See: https://web.archive.org/web/20200228105003/https://www.securityfocus.com/archive/1/315554
+ [000799] /search.asp?term=<%00script>alert('Vulnerable'): ASP.Net 1.1 may allow Cross Site Scripting (XSS) in error pages (only some browsers will render this).
+ [000801] /samples/search.dll?query=&logic=AND: Sambar Server default script is vulnerable to Cross Site Scripting (XSS).
+ [000802] /replymsg.php?send=1&destin=: This version of PHP-Nuke's replymsg.php is vulnerable to Cross Site Scripting (XSS).
+ [000804] /postnuke/modules.php?op=modload&name=Web_Links&file=index&req=viewlinkdetails&lid=666&ttitle=Mocosoft+Utilities\"%3: Postnuke Phoenix 0.7.2.3 is vulnerable to Cross Site Scripting (XSS).
+ [000806] /pm_buddy_list.asp?name=A&desc=B%22%3E%3Ca%20s=%22&code=1: Web Wiz Forums ver. 7.01 and below is vulnerable to Cross Site Scripting (XSS). See: https://www.exploit-db.com/exploits/28589
+ [000809] /phpwebsite/index.php?module=search&SEA_search_op=continue&PDA_limit=10\">: phpWebSite 0.9.x and below are vulnerable to Cross Site Scripting (XSS).
+ [000810] /phpwebsite/index.php?module=pagemaster&PAGE_user_op=view_page&PAGE_id=10\">&MMN_position=[X:X]: phpWebSite 0.9.x and below are vulnerable to Cross Site Scripting (XSS).
+ [000811] /phpwebsite/index.php?module=fatcat&fatcat[user]=viewCategory&fatcat_id=1%00+\">: phpWebSite 0.9.x and below are vulnerable to Cross Site Scripting (XSS).
+ [000812] /phpwebsite/index.php?module=calendar&calendar[view]=day&month=2&year=2003&day=1+%00\">: phpWebSite 0.9.x and below are vulnerable to Cross Site Scripting (XSS).
+ [000814] /phptonuke.php?filnavn=: PHP-Nuke add-on PHPToNuke is vulnerable to Cross Site Scripting (XSS). See: https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2002-1995
+ [000816] /phpinfo.php?VARIABLE=: Contains PHP configuration information and is vulnerable to Cross Site Scripting (XSS). See: https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-1287
+ [000817] /phpinfo.php3?VARIABLE=: Contains PHP configuration information and is vulnerable to Cross Site Scripting (XSS). See: https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-1287
+ [000820] /phpBB/viewtopic.php?topic_id=: phpBB is vulnerable to Cross Site Scripting (XSS). Upgrade to the latest version. See: https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2003-0484
+ [000821] /phpBB/viewtopic.php?t=17071&highlight=\">\": phpBB is vulnerable to Cross Site Scripting (XSS). See: https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2003-0484
+ [000822] /phorum/admin/header.php?GLOBALS[message]=: Phorum 3.3.2a and below from phorum.org is vulnerable to Cross Site Scripting (XSS). See: https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2011-3392
+ [000823] /phorum/admin/footer.php?GLOBALS[message]=: Phorum 3.3.2a and below from phorum.org is vulnerable to Cross Site Scripting (XSS). See: OSVhttps://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2011-339244
+ [000826] /Page/1,10966,,00.html?var=: Vignette server is vulnerable to Cross Site Scripting (XSS). Upgrade to the latest version.
+ [000830] /netutils/whodata.stm?sitename=: Sambar Server before 6.0 beta 6 default script is vulnerable to Cross Site Scripting (XSS). See: https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2003-1285
+ [000831] /nav/cList.php?root=: OpenBB 1.0.0 RC3 is vulnerable to Cross Site Scripting (XSS).
+ [000837] /msadm/user/login.php3?account_name=\">: The Sendmail Server Site User login is vulnerable to Cross Site Scripting (XSS).
+ Scan terminated: 4 errors and 59 items reported on the remote host
+ End Time: 2026-04-19 23:00:12 (GMT-4) (91 seconds)
---------------------------------------------------------------------------
+ 1 host(s) tested