primumterminus.com
Executive Summary
Web Application Findings
The path https://primumterminus.com/.env returned HTTP 200. This may expose configuration files, secrets, or API documentation to unauthorized users.
The path https://primumterminus.com/.git/config returned HTTP 200. This may expose configuration files, secrets, or API documentation to unauthorized users.
No CSP header found. The application is vulnerable to cross-site scripting (XSS) and data injection attacks.
No Strict-Transport-Security header found. Users can be downgraded from HTTPS to HTTP via man-in-the-middle attacks.
The path https://primumterminus.com/backup returned HTTP 200. This may expose configuration files, secrets, or API documentation to unauthorized users.
The path https://primumterminus.com/api/docs returned HTTP 200. This may expose configuration files, secrets, or API documentation to unauthorized users.
The path https://primumterminus.com/swagger.json returned HTTP 200. This may expose configuration files, secrets, or API documentation to unauthorized users.
The path https://primumterminus.com/openapi.json returned HTTP 200. This may expose configuration files, secrets, or API documentation to unauthorized users.
The path https://primumterminus.com/robots.txt returned HTTP 200. This may expose configuration files, secrets, or API documentation to unauthorized users.
No X-Frame-Options header found. The application may be vulnerable to clickjacking attacks.
No Permissions-Policy header found. Browser features like camera, microphone, and geolocation are not explicitly restricted.
The SSL certificate for primumterminus.com expires on 2026-07-06. Plan renewal to avoid disruption.
MITRE ATT&CK Mapping
5 techniques identified across 4 tactics
| Technique | Name | Tactic | Findings | Mitigation |
|---|---|---|---|---|
T1059.007 |
Command and Scripting Interpreter: JavaScript | Execution | 1 | M1038 - Execution Prevention; M1040 - Behavior Prevention on Endpoint |
T1189 |
Drive-by Compromise | Initial Access | 1 | M1048 - Application Isolation and Sandboxing; M1050 - Exploit Protection |
T1190 |
Exploit Public-Facing Application | Initial Access | 11 | M1048 - Application Isolation and Sandboxing; M1030 - Network Segmentation; M101... |
T1557 |
Adversary-in-the-Middle | Credential Access / Collection | 2 | M1041 - Encrypt Sensitive Information; M1035 - Limit Access to Resource Over Net... |
T1592 |
Gather Victim Host Information | Reconnaissance | 11 | M1056 - Pre-compromise; minimize public information disclosure |