Scan report for "kikman.com"

Membership level: Free member
Summary

Found

19

Duration

1min 1sec

Date

2025-05-12

IP

199.250.208.144

Report
Nikto scan (max 60 sec) (nikto -host kikman.com -maxtime 60)
- Nikto 
---------------------------------------------------------------------------
+ Target IP:          199.250.208.144
+ Target Hostname:    kikman.com
+ Target Port:        80
+ Start Time:         2025-05-11 23:21:11 (GMT-7)
---------------------------------------------------------------------------
+ Server: Apache
+ /: Retrieved x-powered-by header: PHP/7.2.34.
+ /: The X-Content-Type-Options header is not set. This could allow the user agent to render the content of the site in a different fashion to the MIME type. See: https://www.netsparker.com/web-vulnerability-scanner/vulnerabilities/missing-content-type-header/
+ /: Cookie OCSESSID created without the httponly flag. See: https://developer.mozilla.org/en-US/docs/Web/HTTP/Cookies
+ /: Cookie language created without the httponly flag. See: https://developer.mozilla.org/en-US/docs/Web/HTTP/Cookies
+ /: Cookie currency created without the httponly flag. See: https://developer.mozilla.org/en-US/docs/Web/HTTP/Cookies
+ /: Uncommon header 'x-accel-expires' found, with contents: 0.
+ /: Web Server returns a valid response with junk HTTP methods which may cause false positives.
+ /admin/config.php: PHP Config file may contain database IDs and passwords.
+ /webmail/blank.html: IlohaMail 0.8.10 contains an XSS vulnerability. Previous versions contain other non-descript vulnerabilities.
+ /securecontrolpanel/: Web Server Control Panel.
+ /webmail/: Web based mail package installed.
+ /phpinfo.php: Output from the phpinfo() function was found.
+ /config.php: PHP Config file may contain database IDs and passwords.
+ /cpanel/: Web-based control panel. See: OSVDB-2117
+ /admin/: This might be interesting.
+ /website/: Directory indexing found.
+ /website/: This might be interesting.
+ /img-sys/: Default image directory should not allow directory listing.
+ /admin/index.php: This might be interesting: has been seen in web logs from an unknown scanner.
+ Scan terminated: 0 error(s) and 19 item(s) reported on remote host
+ End Time:           2025-05-11 23:22:12 (GMT-7) (61 seconds)
---------------------------------------------------------------------------
+ 1 host(s) tested
Detailed report
Target
kikman.com
Target IP
199.250.208.144
Scan method
Nikto scan (max 60 sec)
Run command
nikto -host kikman.com -maxtime 60
Duration
Quick report
Scan date
12 May 2025 02:22
Copy scan report
Download report
Remove scan result
$
Total scans
Check ports
API - Scan ID