https://transport.data.gouv.fr

Nmap
severity | service | vulnerability |
info | http (port:80) | |
info | bgp (port:179) | |
info | https (port:443) | |
info | socks (port:1080) | |
info | pvuniwien (port:1081) | |
info | ssh (port:5002) | |
info | smtp (port:5221) | |
info | ssh (port:5357) | |
info | tcpwrapped (port:5666) | |
info | amqp (port:5800) | |
info | tcpwrapped (port:5902) | |
info | smtp (port:5961) | |
info | unknown (port:5962) | |
info | abyss (port:9999) |
Mozilla HTTP observatory
Impact | Description | Documentation |
Content Security Policy (CSP) implemented unsafely. This includes |
Remove | |
Cookies set without using the | Documentation for cookies-secure-with-httponly-sessions | |
| Add HSTS. Consider rolling out with shorter periods first (as suggested on https://hstspreload.org/). |
Scan OWASP
risk | name |
Medium (High) | CSP: Failure to Define Directive with No Fallback |
Medium (High) | CSP: Wildcard Directive |
Medium (High) | CSP: script-src unsafe-eval |
Medium (High) | CSP: script-src unsafe-inline |
Medium (Low) | Absence of Anti-CSRF Tokens |
Low (High) | CSP: Notices |
Low (High) | Strict-Transport-Security Header Not Set |
Low (Medium) | Cookie Without Secure Flag |
Low (Medium) | Insufficient Site Isolation Against Spectre Vulnerability |
Low (Medium) | Permissions Policy Header Not Set |
Informational (High) | Sec-Fetch-Dest Header is Missing |
Informational (High) | Sec-Fetch-Mode Header is Missing |
Informational (High) | Sec-Fetch-Site Header is Missing |
Informational (High) | Sec-Fetch-User Header is Missing |
Informational (Medium) | Base64 Disclosure |
Informational (Medium) | Modern Web Application |
Informational (Medium) | Non-Storable Content |
Informational (Medium) | Session Management Response Identified |
Informational (Low) | Re-examine Cache-control Directives |