HTTP/1.1 200 OK
Date: Mon, 17 Mar 2025 03:14:48 GMT
Content-Type: text/html; charset=UTF-8
Transfer-Encoding: chunked
Connection: keep-alive
Server: Apache/2.4.37 (CentOS Stream) OpenSSL/1.1.1k
X-Powered-By: PHP/7.4.33
Pragma: no-cache
Cache-Control: max-age=0, must-revalidate, no-cache, no-store
Expires: Sun, 17 Mar 2024 03:14:45 GMT
Content-Security-Policy-Report-Only: font-src *.fontawesome.com data: 'self' 'unsafe-inline'; form-action secure.authorize.net test.authorize.net geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com *.amazon.com *.amazon.co.uk *.amazon.co.jp *.amazon.jp *.amazon.it *.amazon.fr *.amazon.es *.amazon.de 'self' 'unsafe-inline'; frame-ancestors 'self'; frame-src fast.amc.demdex.net *.adobe.com secure.authorize.net test.authorize.net geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com *.youtube.com https://www.google.com/recaptcha/ *.amazon.com *.amazon.co.uk *.amazon.co.jp *.amazon.jp *.amazon.it *.amazon.fr *.amazon.es *.amazon.de *.payments-amazon.com *.payments-amazon.co.uk *.payments-amazon.co.jp *.payments-amazon.jp *.payments-amazon.it *.payments-amazon.fr *.payments-amazon.es *.payments-amazon.de c.paypal.com checkout.paypal.com assets.braintreegateway.com pay.google.com *.cardinalcommerce.com 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com data: www.googleadservices.com www.google-analytics.com www.paypalobjects.com t.paypal.com *.ftcdn.net *.behance.net www.paypal.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com d3sbl0c71oxeok.cloudfront.net dhkkzdfmpzvap.cloudfront.net d2bpzs5y44q6e0.cloudfront.net d37shgu97oizpd.cloudfront.net d1zlqll3enr74n.cloudfront.net d1jynp0fpwn93a.cloudfront.net d2cb3tokgpwh3v.cloudfront.net d1re8bfxx3pw6e.cloudfront.net d35u8xwkxs8vpe.cloudfront.net d13s9xffygp5o.cloudfront.net d388nbw0dwi1jm.cloudfront.net d11p2vtu3dppaw.cloudfront.net d3r89hiip86hka.cloudfront.net dc7snq0c8ipyk.cloudfront.net d5c7kvljggzso.cloudfront.net d2h8yg3ypfzua1.cloudfront.net d1b556x7apj5fb.cloudfront.net draz1ib3z71v2.cloudfront.net dr6hdp4s5yzfc.cloudfront.net d2bomicxw8p7ii.cloudfront.net d3aypcdgvjnnam.cloudfront.net d2a3iuf10348gy.cloudfront.net *.ssl-images-amazon.com *.ssl-images-amazon.co.uk *.ssl-images-amazon.co.jp *.ssl-images-amazon.jp *.ssl-images-amazon.it *.ssl-images-amazon.fr *.ssl-images-amazon.es *.ssl-images-amazon.de *.media-amazon.com *.media-amazon.co.uk *.media-amazon.co.jp *.media-amazon.jp *.media-amazon.it *.media-amazon.fr *.media-amazon.es *.media-amazon.de store.paradoxlabs.com www.sandbox.paypal.com b.stats.paypal.com dub.stats.paypal.com assets.braintreegateway.com c.paypal.com checkout.paypal.com https://maps.gstatic.com data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com secure.authorize.net test.authorize.net www.googleadservices.com www.google-analytics.com www.paypalobjects.com js.braintreegateway.com www.paypal.com geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com www.sandbox.paypal.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ *.payments-amazon.com *.payments-amazon.co.uk *.payments-amazon.co.jp *.payments-amazon.jp *.payments-amazon.it *.payments-amazon.fr *.payments-amazon.es *.payments-amazon.de *.avada.io *.authorize.net assets.braintreegateway.com c.paypal.com pay.google.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com https://maps.googleapis.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com *.fontawesome.com unsafe-inline 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net www.google-analytics.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com *.amazon.com *.amazon.co.uk *.amazon.co.jp *.amazon.jp *.amazon.it *.amazon.fr *.amazon.es *.amazon.de *.amazonpay.com *.amazonpay.co.uk *.amazonpay.co.jp *.amazonpay.jp *.amazonpay.it *.amazonpay.fr *.amazonpay.es *.amazonpay.de mws.amazonservices.com mws.amazonservices.co.uk mws.amazonservices.co.jp mws.amazonservices.jp mws.amazonservices.it mws.amazonservices.fr mws.amazonservices.es mws.amazonservices.de https://get.geojs.io *.avada.io *.authorize.net api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.braintree-api.com 'self' 'unsafe-inline'; child-src assets.braintreegateway.com c.paypal.com http: https: blob: 'self' 'unsafe-inline'; default-src 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline';
X-Content-Type-Options: nosniff
X-XSS-Protection: 1; mode=block
X-Frame-Options: SAMEORIGIN
Set-Cookie: PHPSESSID=ucg8jjh1qkqob891frjiipv8gf; expires=Mon, 17-Mar-2025 04:14:45 GMT; Max-Age=3600; path=/; domain=uat.buttercut.com; secure; HttpOnly; SameSite=Lax
Vary: Accept-Encoding
X-UA-Compatible: IE=edge
X-Frame-Options: SAMEORIGIN
SSL Certificate
Certificate:
Data:
Version: 3 (0x2)
Serial Number:
07:fd:5f:c1:94:e4:c6:34:61:e6:8c:a2:ac:57:04:69
Signature Algorithm: sha256WithRSAEncryption
Issuer: C=US, O=Amazon, CN=Amazon RSA 2048 M03
Validity
Not Before: Jul 25 00:00:00 2024 GMT
Not After : Aug 23 23:59:59 2025 GMT
Subject: CN=*.buttercut.com
Subject Public Key Info:
Public Key Algorithm: rsaEncryption
Public-Key: (2048 bit)
Modulus:
00:b7:7f:58:a8:e4:99:10:39:b0:5d:e3:d8:34:98:
fa:b2:f3:17:9d:75:a4:80:64:53:6d:b8:16:a1:ac:
0d:b7:71:7a:65:97:f7:37:b4:94:36:da:7c:1a:25:
48:2e:de:12:13:c4:dc:88:5b:f9:c9:55:97:9e:9b:
81:ea:d3:72:a3:e8:f1:0b:11:39:0a:48:5e:58:fe:
e2:a8:3f:31:6a:91:4d:f4:31:d9:cd:57:bf:b3:c3:
be:66:5d:6d:fc:79:8f:0b:6f:6d:5f:67:c1:14:69:
42:ad:29:60:77:67:a0:e9:21:1b:f7:68:99:23:a9:
9f:95:c2:6c:a0:0a:af:7c:da:0c:9e:29:f6:2b:ca:
1e:36:bc:df:c7:2e:b7:00:46:30:3b:f3:bf:3a:a5:
d0:c5:2d:11:47:65:6a:94:cd:4e:c1:2e:72:dd:a3:
0e:38:9e:58:2a:54:a4:a3:a6:cc:22:51:da:89:49:
1b:57:10:f7:d3:a7:a4:e8:03:56:8a:f6:a1:58:10:
fb:f4:cf:c0:85:50:cf:91:80:a2:f1:ce:ba:b9:9d:
55:90:d6:07:66:a8:2e:ee:a1:83:d2:ac:7a:89:07:
83:9a:ef:88:28:3c:5f:24:3e:27:8e:83:9a:60:33:
94:a7:3c:09:0b:ef:cc:c0:f3:2d:ca:72:64:50:bc:
9b:3b
Exponent: 65537 (0x10001)
X509v3 extensions:
X509v3 Authority Key Identifier:
55:D9:18:5F:D2:1C:CC:01:E1:58:B4:BE:AB:D9:55:42:01:D7:2E:02
X509v3 Subject Key Identifier:
DB:84:87:4A:7D:E6:09:58:4C:53:0A:68:94:89:3E:6D:4C:D1:E7:89
X509v3 Subject Alternative Name:
DNS:*.buttercut.com
X509v3 Certificate Policies:
Policy: 2.23.140.1.2.1
X509v3 Key Usage: critical
Digital Signature, Key Encipherment
X509v3 Extended Key Usage:
TLS Web Server Authentication, TLS Web Client Authentication
X509v3 CRL Distribution Points:
Full Name:
URI:http://crl.r2m03.amazontrust.com/r2m03.crl
Authority Information Access:
OCSP - URI:http://ocsp.r2m03.amazontrust.com
CA Issuers - URI:http://crt.r2m03.amazontrust.com/r2m03.cer
X509v3 Basic Constraints: critical
CA:FALSE
CT Precertificate SCTs:
Signed Certificate Timestamp:
Version : v1 (0x0)
Log ID : 12:F1:4E:34:BD:53:72:4C:84:06:19:C3:8F:3F:7A:13:
F8:E7:B5:62:87:88:9C:6D:30:05:84:EB:E5:86:26:3A
Timestamp : Jul 25 10:55:46.005 2024 GMT
Extensions: none
Signature : ecdsa-with-SHA256
30:45:02:21:00:82:94:38:97:98:14:05:8B:40:EE:7F:
8B:E2:C1:B8:39:14:0D:17:5B:C5:A7:2F:31:FA:0F:B7:
04:73:CC:99:62:02:20:2B:05:DC:8B:CC:F1:80:DE:27:
BB:5F:F5:D6:72:A3:45:D1:94:4B:E7:64:AD:DD:5D:56:
42:99:73:7B:5C:8F:BA
Signed Certificate Timestamp:
Version : v1 (0x0)
Log ID : 7D:59:1E:12:E1:78:2A:7B:1C:61:67:7C:5E:FD:F8:D0:
87:5C:14:A0:4E:95:9E:B9:03:2F:D9:0E:8C:2E:79:B8
Timestamp : Jul 25 10:55:45.882 2024 GMT
Extensions: none
Signature : ecdsa-with-SHA256
30:46:02:21:00:B0:BC:D3:B4:19:00:D9:CD:57:97:CD:
A4:73:A4:1D:F7:8B:E2:E6:CF:1E:0C:FC:EC:3B:91:CC:
EC:3C:93:C8:8B:02:21:00:EF:F0:73:3C:CA:29:D2:4B:
09:DF:59:66:0F:A4:D7:FA:DB:72:6B:EB:9E:23:5A:52:
B7:58:BF:CB:FC:61:AC:0F
Signed Certificate Timestamp:
Version : v1 (0x0)
Log ID : E6:D2:31:63:40:77:8C:C1:10:41:06:D7:71:B9:CE:C1:
D2:40:F6:96:84:86:FB:BA:87:32:1D:FD:1E:37:8E:50
Timestamp : Jul 25 10:55:45.911 2024 GMT
Extensions: none
Signature : ecdsa-with-SHA256
30:44:02:20:51:03:06:D4:D4:F6:8F:63:D6:AC:3A:46:
CF:3D:B0:87:CA:0A:3C:67:60:C8:35:CC:C7:73:CF:82:
D5:D2:EA:18:02:20:37:F9:7B:71:EF:66:48:62:81:41:
CA:E5:1A:D5:FA:59:29:F4:A7:F6:E0:01:E8:B8:5F:D0:
8C:2B:3A:E7:41:0B
Signature Algorithm: sha256WithRSAEncryption
Signature Value:
33:46:9a:53:74:a1:3b:0c:79:83:52:97:a1:35:94:fb:fd:23:
db:61:b2:6a:ef:75:be:93:b4:ae:bd:44:0f:06:07:b1:b5:ec:
a1:da:ee:65:8d:c9:cc:6d:f9:27:57:43:58:aa:69:43:41:37:
fc:99:a5:99:10:7f:70:d1:46:c9:a5:cd:ae:fa:2f:59:70:70:
63:1e:47:07:b3:a7:72:57:22:61:68:a9:78:a5:df:84:b7:a7:
e4:e0:3e:c8:55:14:e9:06:ee:10:65:81:50:e1:cb:2d:aa:4f:
ff:95:d7:0c:b4:63:a3:9d:f6:4b:13:a9:0e:9c:fa:01:23:94:
01:3f:5a:89:7b:d7:f8:83:0c:b0:2c:d0:8d:d5:8d:0a:6b:dc:
79:36:5f:16:6e:06:54:26:ba:f2:bb:5e:dd:f6:4a:6c:7a:ff:
7c:58:5e:9c:1d:ef:dd:a5:aa:9a:1b:27:ef:84:e2:87:55:d2:
c2:fc:1c:06:89:5c:b2:1a:41:4f:f5:65:92:70:b8:e2:3f:78:
13:6f:02:b0:71:69:b6:3d:19:48:29:96:2a:f6:11:fb:0d:7c:
a1:77:7a:98:cd:cf:28:2b:0a:c1:71:60:d5:6f:ef:96:3a:f3:
57:70:65:2a:c0:9a:eb:49:40:56:a8:51:28:3e:6f:41:8a:c7:
82:d4:45:9b
Vulnerabilities