Found
Duration
Date
IP
- Nikto --------------------------------------------------------------------------- + Target IP: 199.250.208.144 + Target Hostname: kikman.com + Target Port: 80 + Start Time: 2025-05-11 23:21:11 (GMT-7) --------------------------------------------------------------------------- + Server: Apache + /: Retrieved x-powered-by header: PHP/7.2.34. + /: The X-Content-Type-Options header is not set. This could allow the user agent to render the content of the site in a different fashion to the MIME type. See: https://www.netsparker.com/web-vulnerability-scanner/vulnerabilities/missing-content-type-header/ + /: Cookie OCSESSID created without the httponly flag. See: https://developer.mozilla.org/en-US/docs/Web/HTTP/Cookies + /: Cookie language created without the httponly flag. See: https://developer.mozilla.org/en-US/docs/Web/HTTP/Cookies + /: Cookie currency created without the httponly flag. See: https://developer.mozilla.org/en-US/docs/Web/HTTP/Cookies + /: Uncommon header 'x-accel-expires' found, with contents: 0. + /: Web Server returns a valid response with junk HTTP methods which may cause false positives. + /admin/config.php: PHP Config file may contain database IDs and passwords. + /webmail/blank.html: IlohaMail 0.8.10 contains an XSS vulnerability. Previous versions contain other non-descript vulnerabilities. + /securecontrolpanel/: Web Server Control Panel. + /webmail/: Web based mail package installed. + /phpinfo.php: Output from the phpinfo() function was found. + /config.php: PHP Config file may contain database IDs and passwords. + /cpanel/: Web-based control panel. See: OSVDB-2117 + /admin/: This might be interesting. + /website/: Directory indexing found. + /website/: This might be interesting. + /img-sys/: Default image directory should not allow directory listing. + /admin/index.php: This might be interesting: has been seen in web logs from an unknown scanner. + Scan terminated: 0 error(s) and 19 item(s) reported on remote host + End Time: 2025-05-11 23:22:12 (GMT-7) (61 seconds) --------------------------------------------------------------------------- + 1 host(s) tested