Reporte de vulnerabilidades

URL: https://d4js8ov38h4k9.cloudfront.net/  ·  CMS: static  ·  Generado: 2026-06-11 22:02:16  ·  ID: 2c6b3f500aa9
31
Total hallazgos
0
Crítico
0
Alto
5
Medio
4
Bajo
22
Info

Nuclei CVEs y templates (18)

SeveridadHallazgo
info [waf-detect:cloudfront] [http] [info] https://d4js8ov38h4k9.cloudfront.net/
info [wordpress-detect] [http] [info] https://d4js8ov38h4k9.cloudfront.net/
info [csp-script-src-wildcard] [http] [info] https://d4js8ov38h4k9.cloudfront.net/
info [weak-csp-detect:unsafe-script-src] [http] [info] https://d4js8ov38h4k9.cloudfront.net/ ["default-src 'self';script-src 'self' 'unsafe-inline' 'unsafe-eval' *.googletagmanager.com *.google-analytics.com analytics.google.com *.doubleclick.net *.googletagservices.com www.googleadservices.com *.clarity.ms *.bing.com script.hotjar.com static.hotjar.com cdn.mouseflow.com *.hs-scripts.com *.hs-analytics.net *.hs-banner.com *.hubspot.com connect.facebook.net static.ads-twitter.com analytics.tiktok.com *.teads.tv *.embluemail.com *.visualwebsiteoptimizer.com www.youtube.com viveupc.pe *.upc.edu.pe web-chat.global.assistant.watson.appdomain.cloud *.b-cdn.net *.hsforms.net *.hsforms.com js.hscta.net *.hsadspixel.net *.hscollectedforms.net static.hsappstatic.net *.googleapis.com *.chattigo.com *.getclicky.com www.googleoptimize.com *.googlesyndication.com *.mathtag.com *.cloudflare.com unpkg.com *.getblue.io snap.licdn.com code.jquery.com *.zonka.co *.usemessages.com cdn.userway.org cdn4.mxpnl.com getbootstrap.com *.hubspotusercontent-na1.net a.mgid.com;style-src 'self' 'unsafe-inline' fonts.googleapis.com cdn.jsdelivr.net www.googletagmanager.com *.upc.edu.pe *.hubspot.com *.b-cdn.net *.chattigo.com *.hsforms.net *.cloudflare.com cdn.userway.org *.googleapis.com getbootstrap.com;img-src 'self' data: blob: *.google-analytics.com *.googletagmanager.com *.doubleclick.net *.clarity.ms *.bing.com *.hotjar.com *.hubspot.com *.hubspotusercontent.com *.hs-banner.com www.facebook.com t.co i.ytimg.com res.cloudinary.com fonts.gstatic.com *.teads.tv analytics.tiktok.com *.embluemail.com *.upc.edu.pe *.b-cdn.net *.hsforms.net *.hsforms.com js.hscta.net www.google.com.pe maps.gstatic.com maps.googleapis.com www.google.com static.hsappstatic.net *.cloudflare.com *.linkedin.com cdn.userway.org cdn.cibertec.edu.pe *.hubspotusercontent-na1.net;font-src 'self' data: fonts.gstatic.com stordatamiupc.blob.core.windows.net *.upc.edu.pe *.hubspot.com *.b-cdn.net *.chattigo.com fonts.googleapis.com *.cloudflare.com cdn.userway.org;media-src 'self' *.chattigo.com cdn.userway.org api.userway.org *.hubspotusercontent-na1.net;connect-src 'self' *.google-analytics.com *.google.com *.doubleclick.net *.clarity.ms *.bing.com *.hotjar.com *.hotjar.io wss://*.hotjar.com n2.mouseflow.com *.hubspot.com *.hs-analytics.net *.hsforms.com *.hscollectedforms.net *.facebook.com analytics.tiktok.com *.teads.tv *.embluemail.com integrations.us-south.assistant.watson.appdomain.cloud viveupc.pe *.upc.edu.pe dev.visualwebsiteoptimizer.com *.hs-banner.com gw.stape.ws searchs-open-portals.azurewebsites.net js.hscta.net static.hsappstatic.net *.googleapis.com *.hubapi.com *.stage01.link *.chattigo.com wss://channels.chattigo.com *.googlesyndication.com *.youtube.com am1.device-api.indigitall.com *.linkedin.com *.cloudflare.com cdn.userway.org cdn77.api.userway.org api.userway.org connect.facebook.net *.b-cdn.net in.getclicky.com;frame-src 'self' *.hubspot.com *.hsforms.com *.hotjar.com *.googletagmanager.com www.youtube.com youtube.com www.youtube-nocookie.com *.doubleclick.net www.facebook.com *.teads.tv *.upc.edu.pe *.b-cdn.net *.hsforms.net *.hs-sites.com event.getblue.io *.google.com *.cloudflare.com cdn.userway.org;frame-ancestors 'self' *.upc.edu.pe;worker-src 'self' blob: *.hotjar.com;object-src 'none';upgrade-insecure-requests;form-action 'self' www.facebook.com *.hsforms.com *.hubspot.com *.hubapi.com *.userway.org;report-uri 'none';report-to 'none';base-uri 'self';"]
info [xss-deprecated-header] [http] [info] https://d4js8ov38h4k9.cloudfront.net/ ["1; mode=block"]
info [aws-bucket-service] [http] [info] https://d4js8ov38h4k9.cloudfront.net/
info [aws-cloudfront-service] [http] [info] https://d4js8ov38h4k9.cloudfront.net/
info [hotjar-rum-detect] [http] [info] https://d4js8ov38h4k9.cloudfront.net/
info [http-missing-security-headers:cross-origin-embedder-policy] [http] [info] https://d4js8ov38h4k9.cloudfront.net/
info [http-missing-security-headers:cross-origin-opener-policy] [http] [info] https://d4js8ov38h4k9.cloudfront.net/
info [http-missing-security-headers:cross-origin-resource-policy] [http] [info] https://d4js8ov38h4k9.cloudfront.net/
info [aws-detect:aws-cloudfront] [http] [info] https://d4js8ov38h4k9.cloudfront.net/
info [aws-detect:aws-kms] [http] [info] https://d4js8ov38h4k9.cloudfront.net/
info [missing-sri] [http] [info] https://d4js8ov38h4k9.cloudfront.net/ ["https://llmometrics.b-cdn.net/metric.js","https://cdnjs.cloudflare.com/ajax/libs/popper.js/1.12.9/umd/popper.min.js"]
info [exposed-gitignore] [http] [info] https://d4js8ov38h4k9.cloudfront.net/.gitignore
info [tech-detect:google-tag-manager] [http] [info] https://d4js8ov38h4k9.cloudfront.net/
info [tech-detect:font-awesome] [http] [info] https://d4js8ov38h4k9.cloudfront.net/
info [tech-detect:bootstrap] [http] [info] https://d4js8ov38h4k9.cloudfront.net/

Retire.js Librerías JS vulnerables (0)

Sin librerías JS vulnerables detectadas.

Nikto Servidor web (0)

Sin hallazgos de Nikto.

WPScan WordPress (0)

Sin vulnerabilidades de WPScan.

OWASP ZAP Active scan (13)

RiesgoAlertaURL afectada
Medium (High) CSP: script-src unsafe-eval https://d4js8ov38h4k9.cloudfront.net/
Medium (High) CSP: script-src unsafe-inline https://d4js8ov38h4k9.cloudfront.net/
Medium (High) CSP: style-src unsafe-inline https://d4js8ov38h4k9.cloudfront.net/
Medium (High) Sub Resource Integrity Attribute Missing https://d4js8ov38h4k9.cloudfront.net/
Medium (Medium) Vulnerable JS Library https://d4js8ov38h4k9.cloudfront.net/static/js/bootstrap.min.js
Low (High) CSP: Notices https://d4js8ov38h4k9.cloudfront.net/
Low (Medium) Cross-Domain JavaScript Source File Inclusion https://d4js8ov38h4k9.cloudfront.net/
Low (High) Server Leaks Version Information via "Server" HTTP Response Header Field https://d4js8ov38h4k9.cloudfront.net/
Low (Low) Timestamp Disclosure - Unix https://d4js8ov38h4k9.cloudfront.net/admision/modalidades-de-ingreso-upc/
Informational (Medium) Information Disclosure - Suspicious Comments https://d4js8ov38h4k9.cloudfront.net/admision/
Informational (Medium) Modern Web Application https://d4js8ov38h4k9.cloudfront.net/
Informational (Low) Re-examine Cache-control Directives https://d4js8ov38h4k9.cloudfront.net/
Informational (Medium) Retrieved from Cache https://d4js8ov38h4k9.cloudfront.net/static/css/main.css