January 29, 2024

Vulnerability Scan Report

prepared by

HostedScan Security

hostedscan.com
HostedScan Security
Vulnerability Scan Report

Overview

Executive Summary
Vulnerability Scan Report

Executive Summary

Vulnerability scans were conducted on selected servers, networks, websites, and applications. This report contains the discovered potential risks from these scans. Risks have been classified into categories according to the level of threat and degree of potential harm they may pose.

Total Risks

Below is the total number of risks found by severity. High risks are the most severe and should be evaluated first. An accepted risk is one which has been manually reviewed and classified as acceptable to not fix at this time, such as a false positive or an intentional part of the system's architecture.

Critical0
High0
Medium0
Low0
Accepted0

Report Coverage

This report includes findings for 1 target that were scanned. Each target is a single URL, IP address, or fully qualified domain name (FQDN).

Vulnerability Categories

Risks By Target
Vulnerability Scan Report

Risks By Target

This section contains the vulnerability findings for each target that was scanned. Prioritize the most vulnerable assets first.

Targets Summary

The total number of risks found for each target, by severity.

Target
Critical
High
Medium
Low
Accepted
00000

Target Breakdowns

The risks discovered for each target.

Risks By Target | imagpro365.com
Vulnerability Scan Report
Target

imagpro365.com

Total Risks

0
0
0
0
0
No risks found.
Active Web Application Vulnerabilities
Vulnerability Scan Report

Active Web Application Vulnerabilities

The OWASP ZAP active web application scan crawls the pages of a web application. It scans for all of the passive scan checks and additionally makes requests and submits forms to actively test an application for even more vulnerabilities. The active scan checks for vulnerabilities such as SQL injection, remote command execution, XSS, and more.

Total Risks

Total number of risks found by severity.

Critical0
High0
Medium0
Low0
Accepted0

Risks Breakdown

Summary list of all detected risks.

TitleThreat LevelOpenAccepted
No risks detected
Passive Web Application Vulnerabilities
Vulnerability Scan Report

Passive Web Application Vulnerabilities

The OWASP ZAP passive web application scan crawls the pages of a web application. It inspects the web pages as well as the requests and responses sent between the server. The passive scan checks for vulnerabilities such as cross-domain misconfigurations, insecure cookies, vulnerable js dependencies, and more.

Total Risks

Total number of risks found by severity.

Critical0
High0
Medium0
Low0
Accepted0

Risks Breakdown

Summary list of all detected risks.

TitleThreat LevelOpenAccepted
No risks detected
SSL/TLS Security
Vulnerability Scan Report

SSL/TLS Security

The SSLyze security scan checks for misconfigured SSL/TLS certificates, expired certificates, weak ciphers, and SSL/TLS vulnerabilities such as Heartbleed.

Total Risks

Total number of risks found by severity.

Critical0
High0
Medium0
Low0
Accepted0

Risks Breakdown

Summary list of all detected risks.

TitleThreat LevelOpenAccepted
No risks detected
Network Vulnerabilities
Vulnerability Scan Report

Network Vulnerabilities

The OpenVAS network vulnerability scan tests servers and internet connected devices for over 50,000 vulnerabilities. OpenVAS uses the Common Vulnerability Scoring System (CVSS) to quantify the severity of findings. 0.0 is the lowest severity and 10.0 is the highest.

Total Risks

Total number of risks found by severity.

Critical0
High0
Medium0
Low0
Accepted0

Risks Breakdown

Summary list of all detected risks.

TitleThreat LevelCVSS ScoreOpenAccepted
No risks detected
Open TCP Ports
Vulnerability Scan Report

Open TCP Ports

The NMAP TCP port scan discovers open TCP ports with a complete scan of ports 0 to 65535.

Total Risks

Total number of risks found by severity.

Critical0
High0
Medium0
Low0
Accepted0

Risks Breakdown

Summary list of all detected risks.

TitleThreat LevelOpenAccepted
No risks detected
Open UDP Ports
Vulnerability Scan Report

Open UDP Ports

The NMAP UDP port scan discovers open ports of common UDP services

Total Risks

Total number of risks found by severity.

Critical0
High0
Medium0
Low0
Accepted0

Risks Breakdown

Summary list of all detected risks.

TitleThreat LevelOpenAccepted
No risks detected
Glossary
Vulnerability Scan Report

Glossary

Accepted Risk
An accepted risk is one which has been manually reviewed and classified as acceptable to not fix at this time, such as a false positive or an intentional part of the system's architecture.
Active Web Application Vulnerabilities
The OWASP ZAP active web application scan crawls the pages of a web application. It scans for all of the passive scan checks and additionally makes requests and submits forms to actively test an application for even more vulnerabilities. The active scan checks for vulnerabilities such as SQL injection, remote command execution, XSS, and more.
Fully Qualified Domain Name (FQDN)
A fully qualified domain name is a complete domain name for a specific website or service on the internet. This includes not only the website or service name, but also the top-level domain name, such as .com, .org, .net, etc. For example, 'www.example.com' is an FQDN.
Passive Web Application Vulnerabilities
The OWASP ZAP passive web application scan crawls the pages of a web application. It inspects the web pages as well as the requests and responses sent between the server. The passive scan checks for vulnerabilities such as cross-domain misconfigurations, insecure cookies, vulnerable js dependencies, and more.
Network Vulnerabilities
The OpenVAS network vulnerability scan tests servers and internet connected devices for over 50,000 vulnerabilities. OpenVAS uses the Common Vulnerability Scoring System (CVSS) to quantify the severity of findings. 0.0 is the lowest severity and 10.0 is the highest.
Open TCP Ports
The NMAP TCP port scan discovers open TCP ports with a complete scan of ports 0 to 65535.
Open UDP Ports
The NMAP UDP port scan discovers open ports of common UDP services
Risk
A risk is a finding from a vulnerability scan. Each risk is a potential security issue that needs review. Risks are assigned a threat level which represents the potential severity.
SSL/TLS Security
The SSLyze security scan checks for misconfigured SSL/TLS certificates, expired certificates, weak ciphers, and SSL/TLS vulnerabilities such as Heartbleed.
Target
A target represents target is a single URL, IP address, or fully qualified domain name (FQDN) that was scanned.
Threat Level
The threat level represents the estimated potential severity of a particular risk. Threat level is divided into 4 categories: High, Medium, Low and Accepted.
Threat Level
The threat level represents the estimated potential severity of a particular risk. Threat level is divided into 5 categories: Critical, High, Medium, Low and Accepted.
CVSS Score
The CVSS 3.0 score is a global standard for evaluating vulnerabilities with a 0 to 10 scale. CVSS maps to threat levels: 0.1 - 3.9 = Low, 4.0 - 6.9 = Medium, 7.0 - 8.9 = High, 9.0 - 10.0 = Critical

This report was prepared using

HostedScan Security ®

For more information, visit hostedscan.com

Founded in Seattle, Washington in 2019, HostedScan, LLC. is dedicated to making continuous vulnerability scanning and risk management much more easily accessible to more businesses.

HostedScan, LLC.

2212 Queen Anne Ave N

Suite #521

Seattle, WA 98109