Found
Duration
Date
IP
- Nikto v2.6.0 --------------------------------------------------------------------------- + Target IP: 13.248.137.138 + Target Hostname: www.competiscan.com + Target Port: 80 + Platform: Unknown + Start Time: 2026-08-14 06:50:24 (GMT-4) --------------------------------------------------------------------------- + Server: Apache/2.4.61 (Amazon) PHP/5.6.40 + Multiple IPs found: 13.248.137.138, 76.223.12.112 + [999986] /: Retrieved x-powered-by header: PHP/5.6.40. + [750500] /icons/: Directory indexing found. + [999962] /: Server banner changed from 'Apache/2.4.61 (Amazon) PHP/5.6.40' to 'awselb/2.0'. + [013587] /: Suggested security header missing: x-content-type-options. See: https://developer.mozilla.org/en-US/docs/Web/HTTP/Headers/X-Content-Type-Options + [013587] /: Suggested security header missing: strict-transport-security. See: https://developer.mozilla.org/en-US/docs/Web/HTTP/Headers/Strict-Transport-Security + [013587] /: Suggested security header missing: referrer-policy. See: https://developer.mozilla.org/en-US/docs/Web/HTTP/Headers/Referrer-Policy + [013587] /: Suggested security header missing: permissions-policy. See: https://developer.mozilla.org/en-US/docs/Web/HTTP/Headers/Permissions-Policy + [95] /: Cookie PHPSESSID created without the httponly flag. See: https://developer.mozilla.org/en-US/docs/Web/HTTP/Cookies + [600050] Apache/2.4.61 appears to be outdated (current is at least 2.4.66). + [600625] PHP/5.6.40 appears to be outdated (current is at least 8.5.1). + [800262] /: PHP/5.6 - PHP 3/4/5 and 7.0 are End of Life products without support. + [000427] /: Link header(s) found with value(s): <https://www.competiscan.com/wp-json/>; rel="https://api.w.org/",<https://www.competiscan.com/>; rel=shortlink. See: https://developer.mozilla.org/en-US/docs/Web/HTTP/Headers/Link + [999967] /: Web Server returns a valid response with junk HTTP methods which may cause false positives. + [999972] /: DEBUG HTTP verb may show server debugging information. See: https://docs.microsoft.com/en-us/visualstudio/debugger/how-to-enable-debugging-for-aspnet-applications?view=vs-2017 + [000777] /user.php?op=confirmnewuser&module=NS-NewUser&uNikto=%22%3E%3Cimg%20src=%22javascript:alert(document.cookie);%22%3E&email=test@test.com: Post Nuke 0.7.2.3-Phoenix is vulnerable to Cross Site Scripting (XSS). + Scan terminated: 0 errors and 15 items reported on the remote host + End Time: 2026-08-14 06:51:25 (GMT-4) (61 seconds) --------------------------------------------------------------------------- + 1 host(s) tested