Found
Duration
Date
IP
- Nikto --------------------------------------------------------------------------- + Target IP: 68.178.202.233 + Target Hostname: cameronrajput.com + Target Port: 80 + Start Time: 2025-06-19 18:44:35 (GMT-7) --------------------------------------------------------------------------- + Server: Apache + /: The X-Content-Type-Options header is not set. This could allow the user agent to render the content of the site in a different fashion to the MIME type. See: https://www.netsparker.com/web-vulnerability-scanner/vulnerabilities/missing-content-type-header/ + /: Directory indexing found. + No CGI Directories found (use '-C all' to force check all possible dirs) + OPTIONS: Allowed HTTP Methods: GET, POST, OPTIONS, HEAD . + /./: Directory indexing found. + /./: Appending '/./' to a directory allows indexing. + /webmail/blank.html: IlohaMail 0.8.10 contains an XSS vulnerability. Previous versions contain other non-descript vulnerabilities. + /securecontrolpanel/: Web Server Control Panel. + /webmail/: Web based mail package installed. + //: Directory indexing found. + //: Apache on Red Hat Linux release 9 reveals the root directory listing by default if there is no index page. + /%2e/: Directory indexing found. + /%2e/: Weblogic allows source code or directory listing, upgrade to v6.0 SP1 or higher. See: https://web.archive.org/web/20171102042459/http://www.securityfocus.com/bid/2513 + ///: Directory indexing found. + /?PageServices: The remote server may allow directory listings through Web Publisher by forcing the server to show all files via 'open directory browsing'. Web Publisher should be disabled. See: http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-1999-0269 + /?wp-cs-dump: The remote server may allow directory listings through Web Publisher by forcing the server to show all files via 'open directory browsing'. Web Publisher should be disabled. See: http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-1999-0269 + /cpanel/: Web-based control panel. See: OSVDB-2117 + /img-sys/: Default image directory should not allow directory listing. + /webmail/lib/emailreader_execute_on_each_page.inc.php: This might be interesting: has been seen in web logs from an unknown scanner. + ///////////////////////////////////////////////////////////////////////////////////////////////////////////////////////////////////////////////////////////////////////////////////////////////////////////////////////////////////////////////////////////////: Directory indexing found. + ///////////////////////////////////////////////////////////////////////////////////////////////////////////////////////////////////////////////////////////////////////////////////////////////////////////////////////////////////////////////////////////////: Abyss 1.03 reveals directory listing when multiple /'s are requested. See: http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2002-1078 + Scan terminated: 0 error(s) and 20 item(s) reported on remote host + End Time: 2025-06-19 18:45:36 (GMT-7) (61 seconds) --------------------------------------------------------------------------- + 1 host(s) tested