MercadoLibre icon MercadoLibre HackerOne

andes-landings.mercadolibre.com


Endpoints (2 of 2)

Page 1 of 1

Path
Port
Status Code
Content-Length
Title
Resp Headers
/
80
301
162
301 Moved Permanently

Location: https://andes-landings.mercadolibre.com/

Content-Type: text/html

/
443
302
187
None

Location: https://zeroheight.com/sso/share?path=%2F&domain=https%3A%2F%2Fandes-landings.mercadolibre.com&share_id=5e27acce7

Content-Type: text/html

  • Path: /
  • Port: 80
  • Status Code: 301
  • Title: 301 Moved Permanently
  • Date: Mon, 10 Jun 2024 23:47:41 GMT

    Server: nginx

    Location: https://andes-landings.mercadolibre.com/

    Content-Type: text/html

    Content-Length: 162

  • Technologies:

    Nginx

  • First snapshot: 8 months, 4 weeks ago
  • Latest snapshot: 8 months, 4 weeks ago
  • Path: /
  • Port: 443
  • Status Code: 302
  • Title: None
  • Date: Mon, 10 Jun 2024 23:47:41 GMT

    Location: https://zeroheight.com/sso/share?path=%2F&domain=https%3A%2F%2Fandes-landings.mercadolibre.com&share_id=5e27acce7

    X-Runtime: 0.035785

    X-Rack-Cors: miss; no-origin

    Content-Type: text/html; charset=utf-8

    X-Request-Id: 46615b8c-2504-4cc5-a315-f2a6b94439bf

    Cache-Control: no-cache

    Referrer-Policy: origin-when-cross-origin, strict-origin-when-cross-origin

    X-Frame-Options: sameorigin

    Zh-Product-Name: zeroheight

    X-Xss-Protection: 1; mode=block

    X-Download-Options: noopen

    X-Content-Type-Options: nosniff

    Content-Security-Policy: default-src https: 'self'; base-uri 'self'; connect-src *.hotjar.com:* vc.hotjar.io:* surveystats.hotjar.io wss://*.hotjar.com wss://api.appcues.net:* https: 'self' wss://*.zeroheight.dev:* wss://replay.uxtweak.com:* *.google-analytics.com *.analytics.google.com *.googletagmanager.com; font-src 'self' data: script.hotjar.com https:; frame-ancestors 'self'; img-src 'self' https: data: blob: script.hotjar.com *.google-analytics.com *.googletagmanager.com; object-src 'none'; script-src 'strict-dynamic' 'unsafe-eval' https: 'self'; style-src 'self' https: 'unsafe-inline'

    Strict-Transport-Security: max-age=31536000; includeSubDomains; preload

    X-Permitted-Cross-Domain-Policies: none

  • Technologies:

    Hsts

  • First snapshot: 8 months, 4 weeks ago
  • Latest snapshot: 8 months, 4 weeks ago

Page 1 of 1