Found
Duration
Date
IP
- Nikto --------------------------------------------------------------------------- + Target IP: 162.215.226.6 + Target Hostname: anshinfotech.org + Target Port: 80 + Start Time: 2025-06-18 22:58:56 (GMT-7) --------------------------------------------------------------------------- + Server: nginx + /: Retrieved x-powered-by header: PHP/8.1.31. + /:X-Frame-Options header is deprecated and has been replaced with the Content-Security-Policy HTTP header with the frame-ancestors directive instead. See: https://developer.mozilla.org/en-US/docs/Web/HTTP/Headers/X-Frame-Options + /: The X-Content-Type-Options header is not set. This could allow the user agent to render the content of the site in a different fashion to the MIME type. See: https://www.netsparker.com/web-vulnerability-scanner/vulnerabilities/missing-content-type-header/ + No CGI Directories found (use '-C all' to force check all possible dirs) + /help/: Help directory should not be accessible. + /global.inc: PHP-Survey's include file should not be available via the web. Configure the web server to ignore .inc files or change this to global.inc.php. See: http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2002-0614 + /scripts/iisadmin/bdir.htr: This default script shows host info, may allow file browsing and buffer a overrun in the Chunked Encoding data transfer mechanism, request /scripts/iisadmin/bdir.htr??c:\<dir>. See: https://docs.microsoft.com/en-us/security-updates/securitybulletins/2002/MS02-028 + /cartcart.cgi: If this is Dansie Shopping Cart 3.0.8 or earlier, it contains a backdoor to allow attackers to execute arbitrary commands. + /uploadn.asp: An ASP page that allows attackers to upload files to server. + Scan terminated: 0 error(s) and 8 item(s) reported on remote host + End Time: 2025-06-18 22:59:57 (GMT-7) (61 seconds) --------------------------------------------------------------------------- + 1 host(s) tested