Found
Duration
Date
IP
- Nikto --------------------------------------------------------------------------- + Multiple IPs found: 104.22.35.164, 172.67.23.184, 104.22.34.164, 2606:4700:10::6816:23a4, 2606:4700:10::6816:22a4, 2606:4700:10::ac43:17b8 + Target IP: 104.22.35.164 + Target Hostname: culiacan.ambar.tecnm.mx + Target Port: 80 + Start Time: 2025-05-07 08:52:13 (GMT-7) --------------------------------------------------------------------------- + Server: cloudflare + Root page / redirects to: https://culiacan.ambar.tecnm.mx/ + No CGI Directories found (use '-C all' to force check all possible dirs) + /current/modules.php?mod=fm&file=../../../../../../../../../../etc/passwd%00&bn=fm_d1: Uncommon header 'accept-ch' found, with contents: Sec-CH-UA-Bitness, Sec-CH-UA-Arch, Sec-CH-UA-Full-Version, Sec-CH-UA-Mobile, Sec-CH-UA-Model, Sec-CH-UA-Platform-Version, Sec-CH-UA-Full-Version-List, Sec-CH-UA-Platform, Sec-CH-UA, UA-Bitness, UA-Arch, UA-Full-Version, UA-Mobile, UA-Model, UA-Platform-Version, UA-Platform, UA. + /current/modules.php?mod=fm&file=../../../../../../../../../../etc/passwd%00&bn=fm_d1: Uncommon header 'critical-ch' found, with contents: Sec-CH-UA-Bitness, Sec-CH-UA-Arch, Sec-CH-UA-Full-Version, Sec-CH-UA-Mobile, Sec-CH-UA-Model, Sec-CH-UA-Platform-Version, Sec-CH-UA-Full-Version-List, Sec-CH-UA-Platform, Sec-CH-UA, UA-Bitness, UA-Arch, UA-Full-Version, UA-Mobile, UA-Model, UA-Platform-Version, UA-Platform, UA. + /current/modules.php?mod=fm&file=../../../../../../../../../../etc/passwd%00&bn=fm_d1: Uncommon header 'server-timing' found, with contents: chlray;desc="93c1e37a1fbb97ca". + /current/modules.php?mod=fm&file=../../../../../../../../../../etc/passwd%00&bn=fm_d1: Uncommon header 'cf-mitigated' found, with contents: challenge. + /current/modules.php?mod=fm&file=../../../../../../../../../../etc/passwd%00&bn=fm_d1: Uncommon header 'origin-agent-cluster' found, with contents: ?1. + Scan terminated: 0 error(s) and 5 item(s) reported on remote host + End Time: 2025-05-07 08:53:14 (GMT-7) (61 seconds) --------------------------------------------------------------------------- + 1 host(s) tested